Prototype Pollution in Node.js Worker Pool Implementation by Piscina
CVE-2026-102992

9.2CRITICAL

Key Information:

Vendor

Piscinajs

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102992?

Piscina, a Node.js worker pool implementation, has a vulnerability that occurs when it stores ThreadPool.options as a plain object inheriting from Object.prototype. This flaw allows attackers to exploit prototype pollution primitives, injecting malicious inherited values into security-sensitive options. As a result, this could lead to the execution of attacker-controlled code in Node.js worker threads, as inherited execArgv could preload malicious scripts, and an inherited loadBalancer could execute unauthorized code during task scheduling. This vulnerability has been addressed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5, so it is crucial for users to upgrade to these versions.

Affected Version(s)

piscina < 4.9.4 < 4.9.4

piscina >= 5.0.0, < 5.3.2 < 5.0.0, 5.3.2

piscina >= 6.0.0-rc.1, < 6.0.0-rc.5 < 6.0.0-rc.1, 6.0.0-rc.5

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.