PatchSiren cyber security CVE debrief
CVE-2026-107700 ntharim CVE debrief
A critical vulnerability exists in dot-access versions 0.0.3 through 1.0.0, allowing remote attackers to execute JavaScript by supplying crafted paths to the get() function. This is due to the path being concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor and load child_process to run operating system commands in the Node.js process.
- Vendor
- ntharim
- Product
- dot-access
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Node.js developers and administrators using dot-access versions 0.0.3 through 1.0.0 should assess exposure and take mitigation steps. This includes verifying the version of dot-access in use, restricting input to the get() function, and monitoring the Node.js process for suspicious activity. Security teams and vulnerability management teams should also review the vulnerability and implement necessary mitigations.
Why it matters
CVE-2026-107700 is a critical vulnerability in dot-access that allows remote code injection. Node.js deployments using affected versions should verify exposure and apply patches or mitigations.
- Potential for arbitrary code execution
- Elevation of privileges in Node.js process
- Possible data breaches or system compromise
Technical summary
The dot-access package is vulnerable to code injection via the get() path argument. An attacker can supply a crafted path to execute JavaScript, potentially leading to arbitrary code execution. This vulnerability allows remote attackers to execute JavaScript by supplying crafted paths to the get() function. The path is concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor and load child_process to run operating system commands in the Node.js process. Affected Node.js deployments should assess exposure and take mitigation steps.
Defensive priority
High priority for Node.js deployments using dot-access versions 0.0.3 through 1.0.0; verify exposure and apply patches or mitigations.
Recommended defensive actions
- Verify dot-access version and upgrade to a patched version if possible
- Review and restrict input to the get() function to prevent crafted paths
- Monitor Node.js process for suspicious activity
- Perform a thorough review of the system's exposure to the vulnerability
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and references to additional information. The vulnerability exists in dot-access versions 0.0.3 through 1.0.0. Node.js developers and administrators should verify exposure and apply patches or mitigations. Evidence limits suggest verifying affected scope and severity via official advisories.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107700 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107700
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107700 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107700
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107700.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/ntharim/dot-access/blob/v1.0.0/index.js
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/ntharim/dot-access
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/dot-access-0.0.3-through-1.0.0-code-injection-via-get-path-argument
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.