---
id: CVE-2026-107701
title: >-
  dot-access through 1.0.0 contains a prototype pollution vulnerability that
  allows attackers to modify Object.prototype by supplying a crafted dotted path
  to set()
summary: >-
  dot-access through 1.0.0 contains a prototype pollution vulnerability that
  allows attackers to modify Object.prototype by supplying a crafted dotted path
  to set(). Attackers controlling the path, such as through user-supplied field
  names…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'
cwe:
  - CWE-1321
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:53.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107701'
references:
  - url: 'https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntharim/dot-access'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntharim/dot-access/blob/v1.0.0/index.js#L9-L18'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/ntharim/dot-access/issues/5'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dot-access-through-1.0.0-prototype-pollution-via-set-path-argument
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-08T20:06:22.188Z'
---

## Overview

dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use __proto__ segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
