Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1. | |
| Title | Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-02T17:29:40.500Z
Reserved: 2026-10-02T14:38:43.244Z
Link: CVE-2026-104848
No data.
Status : Received
Published: 2026-10-02T17:17:03.473
Modified: 2026-10-02T17:17:03.473
Link: CVE-2026-104848
No data.
OpenCVE Enrichment
Updated: 2026-10-02T17:30:18Z
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')