CVE-2026-107701 is a high-severity vulnerability in the dot-access package, which allows attackers to pollute the Object prototype by supplying a crafted dotted path to the set() function. This can lead to various impacts, including altering authorization flags and option defaults or crashing the process. The vulnerability affects systems using the dot-access package, particularly those with user-supplied [truncated]
A critical vulnerability exists in dot-access versions 0.0.3 through 1.0.0, allowing remote attackers to execute JavaScript by supplying crafted paths to the get() function. This is due to the path being concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor and load child_process to run operating system commands in the Node.js process.