Prototype Pollution in Node.js Worker Pool Implementation by Piscina
CVE-2026-102992
What is CVE-2026-102992?
Piscina, a Node.js worker pool implementation, has a vulnerability that occurs when it stores ThreadPool.options as a plain object inheriting from Object.prototype. This flaw allows attackers to exploit prototype pollution primitives, injecting malicious inherited values into security-sensitive options. As a result, this could lead to the execution of attacker-controlled code in Node.js worker threads, as inherited execArgv could preload malicious scripts, and an inherited loadBalancer could execute unauthorized code during task scheduling. This vulnerability has been addressed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5, so it is crucial for users to upgrade to these versions.
Affected Version(s)
piscina < 4.9.4 < 4.9.4
piscina >= 5.0.0, < 5.3.2 < 5.0.0, 5.3.2
piscina >= 6.0.0-rc.1, < 6.0.0-rc.5 < 6.0.0-rc.1, 6.0.0-rc.5
