Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ariperkki

#28989of 57,579
9.5Total CVSS
Vulnerabilities · 1
PT-2026-104402
9.5
2026-10-02
Npm · Tinypool · CVE-2026-104848
**Name of the Vulnerable Software and Affected Versions** Tinypool versions prior to 2.1.1 **Description** Tinypool constructs `ThreadPool.options` from a standard options object and reads the `execArgv` and `env` worker options in `dist/index.js`. This process allows values inherited from a polluted `Object.prototype` to be copied into own properties and passed to `worker threads.Worker`. An attacker capable of polluting either property can force newly spawned workers to load attacker-selected JavaScript via command-line preload arguments or `NODE OPTIONS`. This leads to code execution with the privileges of the host process, potentially granting access to CI secrets, signing material, or build artifacts. **Recommendations** Update to version 2.1.1.