Description
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.
Published: 2026-10-08
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path value is concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor, load child_process, and run operating system commands in the Node.js process.

Affected Systems

The affected product is dot-access released by ntharim. Vulnerable versions include 0.0.3 up to and including 1.0.0. No other versions are listed as affected.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. EPSS information is not available, but the exploit does not require special conditions beyond supplying a crafted path to get(). The vulnerability is not listed in CISA's KEV catalog, yet the impact of arbitrary code execution is catastrophic for confidentiality, integrity, and availability of the affected Node.js application.

Generated by OpenCVE AI on October 8, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade dot-access to a version newer than 1.0.0 which is not affected by the code injection flaw.
  • If an immediate upgrade is impossible, restrict or disable the use of get() with externally supplied paths and sanitize input paths to eliminate non‑literal characters ensuring they cannot be interpreted as JavaScript.
  • Implement runtime monitoring or firewall rules to block execution of child_process spawning commands issued from the Node.js process until the vulnerability is fully mitigated.

Generated by OpenCVE AI on October 8, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Ntharim
Ntharim dot-access
Vendors & Products Ntharim
Ntharim dot-access

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.
Title dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Ntharim Dot-access
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-09T11:44:39.084Z

Reserved: 2026-10-08T16:52:24.549Z

Link: CVE-2026-107700

cve-icon Vulnrichment

Updated: 2026-10-09T11:44:28.361Z

cve-icon NVD

Status : Deferred

Published: 2026-10-08T19:17:02.213

Modified: 2026-10-09T12:17:09.273

Link: CVE-2026-107700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T08:03:53Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')