Code Execution Vulnerability in Tinypool by Tinylibs
CVE-2026-104848

9.5CRITICAL

Key Information:

Vendor

Tinylibs

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104848?

Tinypool, a lightweight Node.js worker thread pool implementation, had a security flaw that allowed attackers to exploit polluted properties within the options object. This vulnerability enabled an attacker to manipulate the environment settings which could lead to loading malicious JavaScript code in newly spawned worker threads, potentially granting access to sensitive information such as CI secrets, signing materials, or build artifacts. Users are advised to upgrade to version 2.1.1 or later to mitigate these risks.

Affected Version(s)

tinypool < 2.1.1

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.