CVE-2026-107701
Deferred Deferred - Pending Action

Prototype Pollution in dot-access Library

Vulnerability report for CVE-2026-107701, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: VulnCheck

Description

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use __proto__ segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ntharim dot-access 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype pollution issue in the dot-access library through version 1.0.0. It allows attackers to modify Object.prototype by providing a crafted dotted path to the set() function. By including __proto__ segments in the path, attackers can inject properties into all objects, which can alter authorization flags, change option defaults, or crash the application.

Detection Guidance

This vulnerability can be detected by reviewing code that uses the dot-access library version 1.0.0 or earlier. Look for usage of the set() function with user-supplied dotted paths. No specific network or system commands are provided in the context.

Impact Analysis

This vulnerability can lead to unauthorized access or privilege escalation if attackers manipulate authorization flags. It may also cause application crashes or unexpected behavior by altering object properties globally. Systems relying on user-supplied field names or paths are particularly at risk.

Compliance Impact

This vulnerability could lead to unauthorized data modification, access control bypass, or denial of service, which may violate GDPR's integrity and availability requirements or HIPAA's security rule for protecting health information. Prototype pollution may allow attackers to alter application behavior, potentially exposing or corrupting sensitive data.

Mitigation Strategies

Immediately upgrade to a patched version of dot-access beyond 1.0.0 if available. If upgrading is not possible, review and sanitize all user-supplied input used in set() operations to prevent prototype pollution. Consider implementing input validation and output encoding.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107701. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart