Prototype Pollution in dot-access Affected by Vendor-related Risks
CVE-2026-107701

8.8HIGH

Key Information:

Vendor

Ntharim

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107701?

The dot-access library, specifically version 1.0.0, is vulnerable to prototype pollution, which allows attackers to manipulate the Object.prototype. By providing a carefully crafted dotted path during the set() operation, an attacker can exploit this flaw to inject properties into all JavaScript objects. This may lead to unauthorized modifications of critical application settings, disruption of operational processes, and the potential for a denial-of-service scenario. It is crucial for developers using dot-access to implement safeguards against such vulnerabilities to maintain application integrity and security.

Affected Version(s)

dot-access 0 <= 1.0.0

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

William Pierson (Retro16)
.