PT-2026-104402 · Npm · Tinypool
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Tinypool versions prior to 2.1.1
Description
Tinypool constructs
ThreadPool.options from a standard options object and reads the execArgv and env worker options in dist/index.js. This process allows values inherited from a polluted Object.prototype to be copied into own properties and passed to worker threads.Worker. An attacker capable of polluting either property can force newly spawned workers to load attacker-selected JavaScript via command-line preload arguments or NODE OPTIONS. This leads to code execution with the privileges of the host process, potentially granting access to CI secrets, signing material, or build artifacts.Recommendations
Update to version 2.1.1.
Exploit
Fix
RCE
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tinypool