Impact
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path value is concatenated into a new Function body in index.js, enabling attackers to access constructor.constructor, load child_process, and run operating system commands in the Node.js process.
Affected Systems
The affected product is dot-access released by ntharim. Vulnerable versions include 0.0.3 up to and including 1.0.0. No other versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. EPSS information is not available, but the exploit does not require special conditions beyond supplying a crafted path to get(). The vulnerability is not listed in CISA's KEV catalog, yet the impact of arbitrary code execution is catastrophic for confidentiality, integrity, and availability of the affected Node.js application.
OpenCVE Enrichment