Prototype Pollution in Tinypool Node.js Worker Thread Pool Implementation
CVE-2026-104849

9.5CRITICAL

Key Information:

Vendor

Tinylibs

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104849?

Tinypool, a minimal Node.js worker thread pool implementation, is affected by a security flaw that allows prototype pollution. Prior to version 2.1.2, the pool.run(task, options) method fails to ensure that the filename in the options object is an own property. This oversight lets an attacker modify Object.prototype.filename, enabling them to load malicious JavaScript modules. When applications pass custom options to pool.run(), they risk exposing sensitive task data or altering it with elevated privileges. Users are advised to upgrade to version 2.1.2 to mitigate this risk.

Affected Version(s)

tinypool < 2.1.2

References

CVSS V4

Score:
9.5
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.