{"id":"CVE-2026-107701","summary":"dot-access through 1.0.0 Prototype Pollution via set() path argument","details":"dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use __proto__ segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.","modified":"2026-10-10T02:47:23.385426425Z","published":"2026-10-08T18:36:36.315Z","database_specific":{"cwe_ids":["CWE-1321"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107701.json","cna_assigner":"VulnCheck"},"references":[{"type":"WEB","url":"https://www.npmjs.com/package/dot-access"},{"type":"ADVISORY","url":"https://gist.github.com/R3tro16/e094e4318a040f189fd5d2d33e8c3ec2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107701.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107701"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/dot-access-through-1.0.0-prototype-pollution-via-set-path-argument"},{"type":"REPORT","url":"https://github.com/ntharim/dot-access/issues/5"},{"type":"PACKAGE","url":"https://github.com/ntharim/dot-access"},{"type":"ARTICLE","url":"https://github.com/ntharim/dot-access/blob/v1.0.0/index.js#L9-L18"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ntharim/dot-access","events":[{"introduced":"0"},{"fixed":"371c786a9038c6ddeba12c852b86aabe5292df79"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.0"},{"fixed":"1.0.0"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["v0.0.5","0.0.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107701.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N"}]}