{"id":"GHSA-85c8-ppgw-ccpr","summary":"Tinypool: Prototype Pollution Gadget to RCE in run() options","details":"`tinypool` is a fork of `piscina` and inherited the same prototype-pollution surface. When `pool.run(task, options)` is called, the `filename` option is read from the provided `options` object. If that object does not have an own `filename` property, the lookup falls through to `Object.prototype`.\n\nAn attacker who can pollute `Object.prototype.filename` (for example, via a vulnerable `lodash.merge`, `qs.parse`, or similar elsewhere in the application) can make tinypool load and execute an attacker-controlled worker module.\n\nThis is the tinypool counterpart to the piscina root discovery [GHSA-x9g3-xrwr-cwfg](https://github.com/piscinajs/piscina/security/advisories/GHSA-x9g3-xrwr-cwfg).\n\n`pool.run(task)` with no second argument is not affected, because `kDefaultOptions.filename` is `null` and the options object is not user-controlled. The exploit only triggers when the caller passes their own options object to `pool.run()`.\n\n## Impact\n\nArbitrary JavaScript execution in the worker pool. If the application passes attacker-controlled data as the `run()` task and also supplies a `run()` options object, the attacker can redirect execution to a malicious worker that exfiltrates or modifies that data, achieving remote code execution and/or data exfiltration.\n\n## Proof of Concept\n\n```js\n// legitimate-worker.mjs\nexport default async (task) =\u003e ({ by: 'legitimate-worker', processed: task })\n\n// malicious-worker.mjs\nexport default async (task) =\u003e ({ by: 'attacker', stolenRequestBody: task })\n\n// main.js\nimport express from \"express\";\nimport Tinypool from \"tinypool\";\nimport { fileURLToPath } from \"node:url\";\nimport path from \"node:path\";\n\nconst __dirname = path.dirname(fileURLToPath(import.meta.url));\n\n// Simulate upstream prototype pollution (lodash merge, qs parse, etc.)\nObject.prototype.filename = path.join(__dirname, \"malicious-worker.mjs\");\n\nconst pool = new Tinypool({\n  filename: path.join(__dirname, \"legitimate-worker.mjs\"),\n});\n\nexpress()\n  .use(express.json())\n  .post(\"/\", async (req, res) =\u003e {\n    const ac = new AbortController();\n    const result = await pool.run(req.body, { signal: ac.signal });\n    res.json(result);\n  })\n  .listen(31337);\n```\n\n## Suggested fix\n\nRead all user-supplied options from own properties only (`Object.hasOwn` or `Object.prototype.hasOwnProperty.call`) and build the internal `ThreadPool.options` object with a null prototype.","aliases":["CVE-2026-104849"],"modified":"2026-10-05T23:00:05.324545780Z","published":"2026-10-05T22:49:52Z","database_specific":{"github_reviewed_at":"2026-10-05T22:49:52Z","nvd_published_at":"2026-10-02T17:17:03Z","cwe_ids":["CWE-1321","CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104849"},{"type":"WEB","url":"https://github.com/tinylibs/tinypool/pull/135"},{"type":"WEB","url":"https://github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf"},{"type":"PACKAGE","url":"https://github.com/tinylibs/tinypool"},{"type":"WEB","url":"https://github.com/tinylibs/tinypool/releases/tag/v2.1.2"}],"affected":[{"package":{"name":"tinypool","ecosystem":"npm","purl":"pkg:npm/tinypool"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-85c8-ppgw-ccpr/GHSA-85c8-ppgw-ccpr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}