PT-2026-104403 · Npm · Tinypool
CVE-2026-104849
·
Published
2026-10-02
·
Updated
2026-10-03
CVSS v4.0
9.5
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Tinypool versions prior to 2.1.2
Description
Tinypool reads the filename from a caller-supplied options object in the
pool.run(task, options) function without verifying if the property is an own property of the object. This allows a polluted Object.prototype.filename to replace the intended worker module. Applications are affected when a custom options object is passed as the second argument to pool.run(). An attacker capable of prototype pollution can force the worker pool to load arbitrary JavaScript, enabling them to read or modify task data using the privileges of the host process.Recommendations
Update to version 2.1.2.
Fix
Code Injection
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tinypool