CVE-2026-104848: Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
tinypool passes worker options to new Worker() by reading them off a plain object whose prototype is Object.prototype. Options the application did not set are resolved through the prototype chain and then passed explicitly to worker_threads.Worker.
Node core ignores Worker options inherited from Object.prototype. By reading them and passing them explicitly, tinypool re-materialises them as own properties and defeats that protection.
Two keys reach code execution:
execArgv— pollutingObject.prototype.execArgv = ['--require', '/path/to/attacker.js']causes every pool worker to load the attacker’s script.env— pollutingObject.prototype.env = { NODE_OPTIONS: '--require /path/to/attacker.js' }achieves the same via environment injection.
References
- github.com/advisories/GHSA-5gmw-xhrv-c9v3
- github.com/tinylibs/tinypool/commit/24df4e730e7d0857a6d226c9b58f8924227404fd
- github.com/tinylibs/tinypool/pull/134
- github.com/tinylibs/tinypool/releases/tag/v2.1.1
- github.com/tinylibs/tinypool/security/advisories/GHSA-5gmw-xhrv-c9v3
- nvd.nist.gov/vuln/detail/CVE-2026-104848
Code Behaviors & Features
Detect and mitigate CVE-2026-104848 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →