Impact
dot-access v1.0.0 contains a prototype pollution vulnerability that allows an attacker to alter Object.prototype by supplying a crafted dotted path to the set() function. When an attacker controls the path argument—such as through user‑supplied field names—they can insert __proto__ segments to inject properties into all objects. This can change authorization flags, alter application defaults, or cause the process to crash. The weakness is identified as CWE‑1321.
Affected Systems
The vulnerability affects the npm package dot-access owned by ntharim, specifically version 1.0.0. Containers or applications that import this package without updating to a later fixed release are at risk.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector likely originates from any input that allows an attacker to supply a path argument to set(), such as user‑controlled field names in a JSON payload or configuration data. Successful exploitation can lead to pervasive changes across objects in the process, potentially compromising application security or availability.
OpenCVE Enrichment