CVE-2026-107700 - dot-access 0.0.3 through 1.0.0 Code Injection via get() Path Argument
CVE ID :CVE-2026-107700 Published : Oct. 8, 2026, 6:36 p.m. | 52 minutes ago Description :dot-access 0.0.3 through 1.0.0 contains a code injection vulnerability that allows remote attackers to execute JavaScript by supplying crafted paths to get(). The path is concatenated into a new Function...