Cyber & AI intelligence
Wasteland.
Briefs indexed3091
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-107700 2026-10-08

CVE-2026-107700: Critical Code Injection in dot-access npm Package Enables Remote Command Execution

"dot-access versions 0.0.3 through 1.0.0 contain a critical code injection flaw (CVSS 3.1: 9.8). According to the NVD and VulnCheck records, it could allow remote attackers to run operating system commands inside the…"

dot-access versions 0.0.3 through 1.0.0 contain a critical code injection flaw (CVSS 3.1: 9.8). According to the NVD and VulnCheck records, it could allow remote attackers to run operating system commands inside the Node.js process when an application passes attacker-controlled paths to get().

What Is It

CVE-2026-107700 is a code injection vulnerability (CWE-94) in dot-access, an npm package maintained by ntharim. The NVD record says the path argument passed to get() is concatenated into a new Function body in index.js. An attacker who controls that path can reach constructor.constructor, load child_process, and run operating system commands with the privileges of the Node.js process.

VulnCheck disclosed the issue and published it to NVD on 2026-10-08. The NVD record's status is currently "Deferred."

Why It Matters

VulnCheck rates the flaw critical:

Both vectors describe a network-reachable attack with low complexity. It needs no privileges and no user interaction. A successful attack has high impact on confidentiality, integrity and availability. Any application that passes untrusted input as a path to dot-access's get() could allow remote code execution on the host.

None of the sources cited here report active exploitation, and they do not show a CISA Known Exploited Vulnerabilities (KEV) catalog entry for this CVE. Readers should check the KEV catalog directly for current status. The CVSS 4.0 exploit maturity field is "Not Defined." NVD links a public GitHub gist from researcher R3tro16 among its references.

What's Vulnerable

The vulnerable code is in index.js, lines 1–7, at the v1.0.0 tag of the project's GitHub repository.

Patch Status

The supplied NVD and VulnCheck data does not list a fixed version. Every version from 0.0.3 through 1.0.0 is marked affected.

Teams should:

Sources