PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107700 ntharim CVE debrief

A critical vulnerability exists in dot-access versions 0.0.3 through 1.0.0, allowing remote attackers to execute JavaScript by supplying crafted paths to the get() function. This is due to the path being concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor and load child_process to run operating system commands in the Node.js process.

Vendor
ntharim
Product
dot-access
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Node.js developers and administrators using dot-access versions 0.0.3 through 1.0.0 should assess exposure and take mitigation steps. This includes verifying the version of dot-access in use, restricting input to the get() function, and monitoring the Node.js process for suspicious activity. Security teams and vulnerability management teams should also review the vulnerability and implement necessary mitigations.

Why it matters

CVE-2026-107700 is a critical vulnerability in dot-access that allows remote code injection. Node.js deployments using affected versions should verify exposure and apply patches or mitigations.

  • Potential for arbitrary code execution
  • Elevation of privileges in Node.js process
  • Possible data breaches or system compromise

Technical summary

The dot-access package is vulnerable to code injection via the get() path argument. An attacker can supply a crafted path to execute JavaScript, potentially leading to arbitrary code execution. This vulnerability allows remote attackers to execute JavaScript by supplying crafted paths to the get() function. The path is concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor and load child_process to run operating system commands in the Node.js process. Affected Node.js deployments should assess exposure and take mitigation steps.

Defensive priority

High priority for Node.js deployments using dot-access versions 0.0.3 through 1.0.0; verify exposure and apply patches or mitigations.

Recommended defensive actions

  • Verify dot-access version and upgrade to a patched version if possible
  • Review and restrict input to the get() function to prevent crafted paths
  • Monitor Node.js process for suspicious activity
  • Perform a thorough review of the system's exposure to the vulnerability
  • Implement compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions and retest remediated assets
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and references to additional information. The vulnerability exists in dot-access versions 0.0.3 through 1.0.0. Node.js developers and administrators should verify exposure and apply patches or mitigations. Evidence limits suggest verifying affected scope and severity via official advisories.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107700 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107700

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107700 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107700

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107700.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ntharim/dot-access/blob/v1.0.0/index.js

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/ntharim/dot-access

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/dot-access-0.0.3-through-1.0.0-code-injection-via-get-path-argument

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.