PT-2026-104403 · Npm · Tinypool

CVE-2026-104849

·

Published

2026-10-02

·

Updated

2026-10-03

CVSS v4.0

9.5

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Tinypool versions prior to 2.1.2
Description Tinypool reads the filename from a caller-supplied options object in the pool.run(task, options) function without verifying if the property is an own property of the object. This allows a polluted Object.prototype.filename to replace the intended worker module. Applications are affected when a custom options object is passed as the second argument to pool.run(). An attacker capable of prototype pollution can force the worker pool to load arbitrary JavaScript, enabling them to read or modify task data using the privileges of the host process.
Recommendations Update to version 2.1.2.

Fix

Code Injection

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104849

Affected Products

Tinypool