Skip to content
Threat Feed
critical advisory

Remote Code Execution in dot-access Library via Path Injection

The dot-access Node.js library versions 0.0.3 through 1.0.0 are vulnerable to code injection via the get() function, allowing unauthenticated attackers to execute arbitrary system commands.

CVE search metadata

CVE search record: CVE-2026-107700. Severity: critical. CVSS: 9.8. KEV: no. Product: dot-access (0.0.3 - 1.0.0). Brief: Remote Code Execution in dot-access Library via Path Injection. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107700/

The dot-access Node.js package, versions 0.0.3 through 1.0.0, contains a critical code injection vulnerability identified as CVE-2026-107700. The vulnerability exists within the get() function, which improperly handles user-supplied path strings. These strings are concatenated directly into a new Function body within the library's index.js file.

An attacker can supply a malicious path containing JavaScript code that breaks out of the intended function context. By leveraging JavaScript's constructor property, an attacker can access the Function constructor to reach the child_process module. This allows for the execution of arbitrary operating system commands within the context of the Node.js process. This vulnerability is highly dangerous for applications that allow end-users to specify or influence the keys used to retrieve data from object hierarchies. The vulnerability affects any application consuming this version range of dot-access.

Attack Chain

  1. An attacker identifies an application endpoint that passes user-controlled input into the dot-access get() method.
  2. The attacker crafts a malicious path string designed to break out of the function scope.
  3. The crafted payload is sent to the application as an HTTP request parameter.
  4. The vulnerable get() function receives the malicious string and concatenates it into the source code of a new Function constructor.
  5. The JavaScript engine executes the injected code during the Function evaluation phase.
  6. The injected code accesses the Function constructor via the prototype chain to gain elevated execution context.
  7. The code imports the 'child_process' module to interact with the underlying host OS.
  8. The attacker executes arbitrary commands on the server to achieve remote code execution.

Impact

Successful exploitation of CVE-2026-107700 allows for unauthenticated remote code execution. Attackers can gain full control over the Node.js process, potentially leading to unauthorized data access, persistence on the server, or lateral movement within the network. This affects all software products that utilize the dot-access library within the identified version range (0.0.3 - 1.0.0).

Recommendation

Prioritized actions for teams using the dot-access library:

  • Audit all internal applications to identify usage of the dot-access library in the range 0.0.3 through 1.0.0.
  • Upgrade the dot-access package to a patched version if available, or replace the library with a secure alternative.
  • Implement input validation on all paths passed to data-retrieval libraries to ensure they do not contain unexpected JavaScript metacharacters.
  • If immediate patching is not possible, implement WAF rules to detect and block suspicious path structures that include JavaScript function constructors or process execution modules.

Immediate actions

Inventory all applications using dot-access 0.0.3-1.0.0.

Development Teams 24h

Mitigations

Upgrade dot-access to a version beyond 1.0.0.

immediate Development Teams

CVE-2026-107700