Bug 2545291 (CVE-2026-104848) - CVE-2026-104848 tinypool: tinypool: arbitrary code execution via prototype pollution in worker options
Summary: CVE-2026-104848 tinypool: tinypool: arbitrary code execution via prototype po...
Keywords:
Status: NEW
Alias: CVE-2026-104848
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-10-02 16:32 UTC by OSIDB Bzimport
Modified: 2026-10-07 11:59 UTC (History)
40 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-10-02 16:32:25 UTC
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.


Note You need to log in before you can comment on or make changes to this bug.