Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.5
CVE-2026-104848: tinypool may execute attacker code in new workers
CVE-2026-104848 · published 9 days ago
Summary
The tinypool library used for managing Node.js background tasks can be tricked into loading malicious JavaScript when it creates new worker threads. If an attacker can tamper with the default object settings, they can run code with the same rights as your build process, potentially exposing secrets or build artifacts. Update tinypool to version 2.1.1 or later to stop this behavior.
What to do
- Update tinypool to version 2.1.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | tinylibs | tinypool | < 2.1.1 |
| npm | – | tinypool |
<= 2.1.0 < 2.1.1 Fix: upgrade to 2.1.1
|
Original advisory text
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.
References
- https://github.com/tinylibs/tinypool/commit/24df4e730e7d0857a6d226c9b58f89242274...
- https://github.com/tinylibs/tinypool/pull/134
- https://github.com/tinylibs/tinypool/releases/tag/v2.1.1
- https://github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-1048... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-104848 Vendor Advisory
- https://github.com/advisories/GHSA-5gmw-xhrv-c9v3
- https://github.com/tinylibs/tinypool Product
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-1321Prototype Pollution
Timeline
Published2 Oct 2026
Updated11 Oct 2026
First seen2 Oct 2026
Sources
CVE-2026-104848 · NVD
CVE-2026-104848 · MITRE
CVE-2026-104848 · OSV
GHSA-5gmw-xhrv-c9v3 · GHSA
GHSA-5gmw-xhrv-c9v3 · OSV
Track software like this
Free during beta