CVE-2026-107700
Deferred Deferred - Pending Action

Code Injection in dot-access JavaScript Library

Vulnerability report for CVE-2026-107700, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ntharim dot-access 0.0.3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a code injection flaw in the dot-access library versions 0.0.3 through 1.0.0. Attackers can exploit it by providing specially crafted paths to the get() function. The library then uses these paths to construct a new Function object in JavaScript, allowing attackers to inject and execute arbitrary JavaScript code. Specifically, they can access the constructor.constructor property to load the child_process module and run operating system commands within the Node.js process.

Detection Guidance

Check if your system uses the dot-access package versions 0.0.3 through 1.0.0. Search for the package in your project dependencies or Node.js modules. Run 'npm list dot-access' or 'yarn list dot-access' to verify installed versions.

Impact Analysis

If you use a vulnerable version of dot-access, attackers could remotely execute arbitrary commands on your system. This could lead to unauthorized access, data theft, or complete system compromise. The impact includes potential loss of sensitive data, disruption of services, and further lateral movement within your network if the Node.js process has elevated privileges.

Compliance Impact

This vulnerability could lead to violations of GDPR and HIPAA due to unauthorized data access or exfiltration. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A successful exploit may result in data breaches, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Upgrade dot-access to a version beyond 1.0.0 immediately. If upgrading is not possible, remove the package from your project dependencies to prevent exploitation. Review any code using dot-access for potential malicious paths.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107700. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart