CVE-2026-104849
published 2026-10-02CVE-2026-104849: Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in…
PriorityP352critical9.5CVSS 4.0
AVNACLATPPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.39%
30.8th percentile
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| tinylibs | tinypool | < 2.1.2 | 2.1.2 |
| tinylibs | tinypool | >= 0 < 2.1.2 | 2.1.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Tinypool: Prototype Pollution Gadget to RCE in run() options
ghsa·2026-10-05
CVE-2026-104849 [CRITICAL] CWE-1321 Tinypool: Prototype Pollution Gadget to RCE in run() options
Tinypool: Prototype Pollution Gadget to RCE in run() options
`tinypool` is a fork of `piscina` and inherited the same prototype-pollution surface. When `pool.run(task, options)` is called, the `filename` option is read from the provided `options` object. If that object does not have an own `filename` property, the lookup falls through to `Object.prototype`.
An attacker who can pollute `Object.prototype.filename` (for example, via a vulnerable `lodash.merge`, `qs.parse`, or similar elsewhere in the application) can make tinypool load and execute an attacker-controlled worker module.
This is the tinypool counterpart to the piscina root discovery [GHSA-x9g3-xrwr-cwfg](https://github.com/piscinajs/piscina/security/advisories/GHSA-x9g3-xrwr-cwfg).
`pool.run(task)` with no second argument is
VulDB
tinylibs Tinypool up to 2.1.1 pool.run options information disclosure
vuldb·2026-10-02·CVSS 9.5
CVE-2026-104849 [CRITICAL] tinylibs Tinypool up to 2.1.1 pool.run options information disclosure
A vulnerability was found in tinylibs Tinypool up to 2.1.1 and classified as problematic. This issue affects the function pool.run. Such manipulation of the argument options leads to information disclosure.
This vulnerability is documented as CVE-2026-104849. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbfhttps://github.com/tinylibs/tinypool/pull/135https://github.com/tinylibs/tinypool/releases/tag/v2.1.2https://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccprhttps://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr
2026-10-02
Published