GHSA-rhfh-63ph-3pchCriticalCVSS 9.8
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote...
🔗 CVE IDs covered (1)
📋 Description
dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-107700
- https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2
- https://github.com/ntharim/dot-access
- https://github.com/ntharim/dot-access/blob/v1.0.0/index.js#L1-L7
- https://www.vulncheck.com/advisories/dot-access-0.0.3-through-1.0.0-code-injection-via-get-path-argument
- https://github.com/advisories/GHSA-rhfh-63ph-3pch