dot-access versions 0.0.3 through 1.0.0 contain a critical code injection flaw (CVSS 3.1: 9.8). According to the NVD and VulnCheck records, it could allow remote attackers to run operating system commands inside the Node.js process when an application passes attacker-controlled paths to get().
What Is It
CVE-2026-107700 is a code injection vulnerability (CWE-94) in dot-access, an npm package maintained by ntharim. The NVD record says the path argument passed to get() is concatenated into a new Function body in index.js. An attacker who controls that path can reach constructor.constructor, load child_process, and run operating system commands with the privileges of the Node.js process.
VulnCheck disclosed the issue and published it to NVD on 2026-10-08. The NVD record's status is currently "Deferred."
Why It Matters
VulnCheck rates the flaw critical:
- CVSS 3.1: 9.8 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) - CVSS 4.0: 9.3 CRITICAL
Both vectors describe a network-reachable attack with low complexity. It needs no privileges and no user interaction. A successful attack has high impact on confidentiality, integrity and availability. Any application that passes untrusted input as a path to dot-access's get() could allow remote code execution on the host.
None of the sources cited here report active exploitation, and they do not show a CISA Known Exploited Vulnerabilities (KEV) catalog entry for this CVE. Readers should check the KEV catalog directly for current status. The CVSS 4.0 exploit maturity field is "Not Defined." NVD links a public GitHub gist from researcher R3tro16 among its references.
What's Vulnerable
- Vendor: ntharim
- Product: dot-access (
pkg:npm/dot-access) - Affected versions: 0.0.3 through 1.0.0 (inclusive, semver)
- Default status for other versions: unaffected
The vulnerable code is in index.js, lines 1–7, at the v1.0.0 tag of the project's GitHub repository.
Patch Status
The supplied NVD and VulnCheck data does not list a fixed version. Every version from 0.0.3 through 1.0.0 is marked affected.
Teams should:
- Check their dependency trees for
dot-access. - Find any code paths where user-controlled input reaches
get(). - Follow the VulnCheck advisory and the project repository for remediation guidance.