Code Execution Vulnerability in Tinypool by Tinylibs
CVE-2026-104848
9.5CRITICAL
What is CVE-2026-104848?
Tinypool, a lightweight Node.js worker thread pool implementation, had a security flaw that allowed attackers to exploit polluted properties within the options object. This vulnerability enabled an attacker to manipulate the environment settings which could lead to loading malicious JavaScript code in newly spawned worker threads, potentially granting access to sensitive information such as CI secrets, signing materials, or build artifacts. Users are advised to upgrade to version 2.1.1 or later to mitigate these risks.
Affected Version(s)
tinypool < 2.1.1
