PT-2026-103583 · Npm · Piscina

CVE-2026-102992

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions piscina versions prior to 4.9.4 piscina versions prior to 5.3.2 piscina versions prior to 6.0.0-rc.5
Description This issue occurs because the software stores ThreadPool.options as a plain object that inherits from Object.prototype. When a separate prototype pollution primitive is present, an attacker can supply inherited values for security-sensitive options that lack their own defaults. This can lead to the following impacts:
  • An inherited execArgv value passed to the Node.js Worker constructor may preload attacker-controlled code in worker threads.
  • An inherited loadBalancer function may execute during task scheduling.
  • Inherited env values may alter worker environments.
Recommendations Update to version 4.9.4. Update to version 5.3.2. Update to version 6.0.0-rc.5.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102992

Affected Products

Piscina