ZERO
Back
advisoryOSV:CVE-2026-104849

Tinypool: Prototype Pollution Gadget to RCE in run() options

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.

State
Active
Resolution
Fixed in 5e18382a9aaa3344035905384b18a88a9da8c8bb

Affected software

Summary

Details

Resolution

Summary

Details

Aliases

Summary

Details