๐Ÿ” CVE Alert

CVE-2026-104848

UNKNOWN 0.0

Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.

CWE CWE-1321
Vendor tinylibs
Product tinypool
Published Oct 2, 2026
Last Updated Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for tinylibs tinypool

Be the first to know when new unknown vulnerabilities affecting tinylibs tinypool are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

tinylibs / tinypool
< 2.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3 github.com: https://github.com/tinylibs/tinypool/pull/134 github.com: https://github.com/tinylibs/tinypool/commit/24df4e730e7d0857a6d226c9b58f8924227404fd github.com: https://github.com/tinylibs/tinypool/releases/tag/v2.1.1