CVE-2026-104848
published 2026-10-02CVE-2026-104848: Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads…
PriorityP260critical9.5CVSS 4.0
AVNACLATPPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.50%
40.6th percentile
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tinylibs | tinypool | < 2.1.1 | 2.1.1 |
| tinylibs | tinypool | >= 0 < 2.1.1 | 2.1.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
ghsa·2026-10-05
CVE-2026-104848 [CRITICAL] CWE-1321 Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
`tinypool` passes worker options to `new Worker()` by reading them off a plain object whose prototype is `Object.prototype`. Options the application did not set are resolved through the prototype chain and then passed explicitly to `worker_threads.Worker`.
Node core ignores `Worker` options inherited from `Object.prototype`. By reading them and passing them explicitly, tinypool re-materialises them as own properties and defeats that protection.
Two keys reach code execution:
1. **`execArgv`** — polluting `Object.prototype.execArgv = ['--require', '/path/to/attacker.js']` causes every pool worker to load the attacker's script.
2. **`env`** — polluting `Object.prototype.env = { NODE_OPTIONS: '--require
VulDB
tinylibs Tinypool up to 2.1.0 Worker Options dist/index.js prototype pollution
vuldb·2026-10-02·CVSS 9.5
CVE-2026-104848 [CRITICAL] tinylibs Tinypool up to 2.1.0 Worker Options dist/index.js prototype pollution
A vulnerability has been found in tinylibs Tinypool up to 2.1.0 and classified as critical. This vulnerability affects unknown code of the file dist/index.js of the component Worker Options. This manipulation causes improperly controlled modification of object prototype attributes.
This vulnerability is registered as CVE-2026-104848. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/tinylibs/tinypool/commit/24df4e730e7d0857a6d226c9b58f8924227404fdhttps://github.com/tinylibs/tinypool/pull/134https://github.com/tinylibs/tinypool/releases/tag/v2.1.1https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3
2026-10-02
Published