CVE-2026-107701: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in ntharim dot-access
Description
dot-access versions up to 1.0.0 contain a prototype pollution vulnerability that allows attackers to modify the Object.prototype by supplying crafted dotted paths to the set() function. This can lead to injection of properties into all objects, potentially altering authorization flags, option defaults, or causing process crashes.
CVSS v4.0
Score 8.8high
Affected software
ntharim
dot-access
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-107701 describes a prototype pollution vulnerability in the dot-access library through version 1.0.0. The vulnerability arises because the set() function improperly controls modification of Object.prototype when attackers supply crafted dotted paths containing __proto__ segments. This enables attackers to inject or modify properties globally across all objects, which can impact application logic such as authorization or configuration defaults, or cause instability by crashing the process.
Potential Impact
Successful exploitation allows attackers to modify Object.prototype, affecting all objects in the environment. This can lead to unauthorized privilege escalation by altering authorization flags, changing default options that affect application behavior, or causing denial of service via process crashes. The CVSS 4.0 score of 8.8 (high severity) reflects the network attack vector, no required privileges or user interaction, and high impact on integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using untrusted input as dotted paths to the set() function in dot-access. Implement input validation or sanitization to prevent __proto__ segments in user-supplied paths.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-10-08T16:52:24.549Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac7fef32cdf04f656318c14
Added to database: 10/08/2026, 20:37:07 UTC
Last enriched: 10/08/2026, 20:48:18 UTC
Last updated: 10/08/2026, 20:48:18 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.