CVE-2026-104849: Tinypool: Prototype Pollution Gadget to RCE in run() options
tinypool is a fork of piscina and inherited the same prototype-pollution surface. When pool.run(task, options) is called, the filename option is read from the provided options object. If that object does not have an own filename property, the lookup falls through to Object.prototype.
An attacker who can pollute Object.prototype.filename (for example, via a vulnerable lodash.merge, qs.parse, or similar elsewhere in the application) can make tinypool load and execute an attacker-controlled worker module.
This is the tinypool counterpart to the piscina root discovery GHSA-x9g3-xrwr-cwfg.
pool.run(task) with no second argument is not affected, because kDefaultOptions.filename is null and the options object is not user-controlled. The exploit only triggers when the caller passes their own options object to pool.run().
References
- github.com/advisories/GHSA-85c8-ppgw-ccpr
- github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf
- github.com/tinylibs/tinypool/pull/135
- github.com/tinylibs/tinypool/releases/tag/v2.1.2
- github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr
- nvd.nist.gov/vuln/detail/CVE-2026-104849
Code Behaviors & Features
Detect and mitigate CVE-2026-104849 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →