PT-2026-104402 · Npm · Tinypool

·

CVE-2026-104848

·

Published

2026-10-02

·

Updated

2026-10-05

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Tinypool versions prior to 2.1.1
Description Tinypool constructs ThreadPool.options from a standard options object and reads the execArgv and env worker options in dist/index.js. This process allows values inherited from a polluted Object.prototype to be copied into own properties and passed to worker threads.Worker. An attacker capable of polluting either property can force newly spawned workers to load attacker-selected JavaScript via command-line preload arguments or NODE OPTIONS. This leads to code execution with the privileges of the host process, potentially granting access to CI secrets, signing material, or build artifacts.
Recommendations Update to version 2.1.1.

Exploit

Fix

RCE

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104848
GHSA-5GMW-XHRV-C9V3

Affected Products

Tinypool