{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dot-access-0.0.3---1.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dot-access_project:dot-access:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-107700"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["dot-access (0.0.3 - 1.0.0)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","injection","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe dot-access Node.js package, versions 0.0.3 through 1.0.0, contains a critical code injection vulnerability identified as CVE-2026-107700. The vulnerability exists within the get() function, which improperly handles user-supplied path strings. These strings are concatenated directly into a new Function body within the library's index.js file.\u003c/p\u003e\n\u003cp\u003eAn attacker can supply a malicious path containing JavaScript code that breaks out of the intended function context. By leveraging JavaScript's constructor property, an attacker can access the Function constructor to reach the child_process module. This allows for the execution of arbitrary operating system commands within the context of the Node.js process. This vulnerability is highly dangerous for applications that allow end-users to specify or influence the keys used to retrieve data from object hierarchies. The vulnerability affects any application consuming this version range of dot-access.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker identifies an application endpoint that passes user-controlled input into the dot-access get() method.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious path string designed to break out of the function scope.\u003c/li\u003e\n\u003cli\u003eThe crafted payload is sent to the application as an HTTP request parameter.\u003c/li\u003e\n\u003cli\u003eThe vulnerable get() function receives the malicious string and concatenates it into the source code of a new Function constructor.\u003c/li\u003e\n\u003cli\u003eThe JavaScript engine executes the injected code during the Function evaluation phase.\u003c/li\u003e\n\u003cli\u003eThe injected code accesses the Function constructor via the prototype chain to gain elevated execution context.\u003c/li\u003e\n\u003cli\u003eThe code imports the 'child_process' module to interact with the underlying host OS.\u003c/li\u003e\n\u003cli\u003eThe attacker executes arbitrary commands on the server to achieve remote code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-107700 allows for unauthenticated remote code execution. Attackers can gain full control over the Node.js process, potentially leading to unauthorized data access, persistence on the server, or lateral movement within the network. This affects all software products that utilize the dot-access library within the identified version range (0.0.3 - 1.0.0).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for teams using the dot-access library:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all internal applications to identify usage of the dot-access library in the range 0.0.3 through 1.0.0.\u003c/li\u003e\n\u003cli\u003eUpgrade the dot-access package to a patched version if available, or replace the library with a secure alternative.\u003c/li\u003e\n\u003cli\u003eImplement input validation on all paths passed to data-retrieval libraries to ensure they do not contain unexpected JavaScript metacharacters.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement WAF rules to detect and block suspicious path structures that include JavaScript function constructors or process execution modules.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T19:39:44Z","date_published":"2026-10-08T19:39:44Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107700/","summary":"The dot-access Node.js library versions 0.0.3 through 1.0.0 are vulnerable to code injection via the get() function, allowing unauthenticated attackers to execute arbitrary system commands.","title":"Remote Code Execution in dot-access Library via Path Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-107700/"}],"language":"en","title":"CraftedSignal Threat Feed - Dot-Access (0.0.3 - 1.0.0)","version":"https://jsonfeed.org/version/1.1"}