๐Ÿ” CVE Alert

CVE-2026-104849

UNKNOWN 0.0

Tinypool: Prototype Pollution Gadget to RCE in run() options

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.

CWE CWE-94 CWE-1321
Vendor tinylibs
Product tinypool
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for tinylibs tinypool

Be the first to know when new unknown vulnerabilities affecting tinylibs tinypool are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

tinylibs / tinypool
< 2.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr github.com: https://github.com/tinylibs/tinypool/pull/135 github.com: https://github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf github.com: https://github.com/tinylibs/tinypool/releases/tag/v2.1.2