OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-107700 (CVSS 9.3)

NVD · officialPublished Oct 8, 2026Risk 50/100

dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function body in index.js, so attackers can reach constructor.constructor to load child_process and run operating system commands in the Node.js process.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source