Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. tinypool
  4. ›
  5. CVE-2026-104849

CVE-2026-104849: Tinypool: Prototype Pollution Gadget to RCE in run() options

October 5, 2026

tinypool is a fork of piscina and inherited the same prototype-pollution surface. When pool.run(task, options) is called, the filename option is read from the provided options object. If that object does not have an own filename property, the lookup falls through to Object.prototype.

An attacker who can pollute Object.prototype.filename (for example, via a vulnerable lodash.merge, qs.parse, or similar elsewhere in the application) can make tinypool load and execute an attacker-controlled worker module.

This is the tinypool counterpart to the piscina root discovery GHSA-x9g3-xrwr-cwfg.

pool.run(task) with no second argument is not affected, because kDefaultOptions.filename is null and the options object is not user-controlled. The exploit only triggers when the caller passes their own options object to pool.run().

References

  • github.com/advisories/GHSA-85c8-ppgw-ccpr
  • github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf
  • github.com/tinylibs/tinypool/pull/135
  • github.com/tinylibs/tinypool/releases/tag/v2.1.2
  • github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr
  • nvd.nist.gov/vuln/detail/CVE-2026-104849

Code Behaviors & Features

Detect and mitigate CVE-2026-104849 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.1.2

Fixed versions

  • 2.1.2

Solution

Upgrade to version 2.1.2 or above.

Impact 10 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

npm/tinypool/CVE-2026-104849.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 06 Oct 2026 00:17:12 +0000.