Tinylibs Tinypool vulnerabilities
2 known vulnerabilities affecting tinylibs/tinypool.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2026-104848P2CRITICALCVSS 9.5fixed in 2.1.12026-10-02
CVE-2026-104848 [CRITICAL] CWE-1321 CVE-2026-104848: Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An a
ghsanvd
CVE-2026-104849P3CRITICALCVSS 9.5fixed in 2.1.22026-10-02
CVE-2026-104849 [CRITICAL] CWE-94 CVE-2026-104849: Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads file
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-
ghsanvd