Prototype Pollution in Tinypool Node.js Worker Thread Pool Implementation
CVE-2026-104849
9.5CRITICAL
What is CVE-2026-104849?
Tinypool, a minimal Node.js worker thread pool implementation, is affected by a security flaw that allows prototype pollution. Prior to version 2.1.2, the pool.run(task, options) method fails to ensure that the filename in the options object is an own property. This oversight lets an attacker modify Object.prototype.filename, enabling them to load malicious JavaScript modules. When applications pass custom options to pool.run(), they risk exposing sensitive task data or altering it with elevated privileges. Users are advised to upgrade to version 2.1.2 to mitigate this risk.
Affected Version(s)
tinypool < 2.1.2
