---
id: CVE-2026-107700
title: >-
  dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that
  allows remote attackers to execute JavaScript by supplying crafted paths to
  get()
summary: >-
  dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that
  allows remote attackers to execute JavaScript by supplying crafted paths to
  get(). The path is concatenated into a new Function body in index.js, so
  attackers ca…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T12:17:09.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107700'
references:
  - url: 'https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntharim/dot-access'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntharim/dot-access/blob/v1.0.0/index.js#L1-L7'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dot-access-0.0.3-through-1.0.0-code-injection-via-get-path-argument
    label: disclosure@vulncheck.com
  - url: 'https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.188Z'
---

## Overview

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
