
🚨Critical - dot-access get() Function Constructor RCE (CVE-2026-107700) dot-access get() concatenates attacker-controlled path input into a new Function() body; crafted payloads using constructor.constructor can require('child_process') and execute OS commands inside the Node.js process. Leads to remote arbitrary code execution when get() is reachable from untrusted input. 👉Affected: dot-access 0.0.3-1.0.0
