Product
The dot-access Node.js library versions 0.0.3 through 1.0.0 are vulnerable to code injection via the get() function, allowing unauthenticated attackers to execute arbitrary system commands.