SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78179

MEDIUM · CVSS 6.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability in the rexrainbow phaser3-rex-notes library allows for remote manipulation of object prototype attributes through improper control of the argument key in the SetValue function. This could lead to unauthorized modifications that may compromise application integrity. Developers using affected versions should prioritize patching to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-78179
Severity
MEDIUM
CVSS
6.3
EPSS
0.33%

Original NVD Description

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.