{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apiscina_projectpiscinanode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:piscina_project:piscina:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-102992"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["piscina (\u003c 4.9.4, \u003e= 5.0.0 \u003c 5.3.2, \u003e= 6.0.0-rc.1 \u003c 6.0.0-rc.5)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","prototype-pollution","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003ePiscina, a popular Node.js worker pool library, is vulnerable to a prototype pollution gadget that enables remote code execution (RCE) and environment manipulation. The vulnerability (CVE-2026-102992) stems from how the \u003ccode\u003eThreadPool\u003c/code\u003e class constructs its internal options object. By using object spread syntax (\u003ccode\u003e{ ...kDefaultOptions, ...options }\u003c/code\u003e) on a plain object that inherits from \u003ccode\u003eObject.prototype\u003c/code\u003e, Piscina inadvertently honors properties present in the global prototype if they are not explicitly defined in the options provided to the constructor.\u003c/p\u003e\n\u003cp\u003eAn attacker who can influence the application state to pollute \u003ccode\u003eObject.prototype\u003c/code\u003e can inject malicious configuration values. The most critical vector is the \u003ccode\u003eexecArgv\u003c/code\u003e property, which allows an attacker to force worker threads to load an arbitrary module via the \u003ccode\u003e--require\u003c/code\u003e flag upon initialization. Other vectors include the \u003ccode\u003eloadBalancer\u003c/code\u003e function, which can be manipulated to execute arbitrary logic during task scheduling, and the \u003ccode\u003eenv\u003c/code\u003e property, which allows for the injection of environment variables into worker processes. This issue persists in Piscina versions \u0026lt; 4.9.4, 5.0.0 through 5.3.1, and 6.0.0-rc.1 through 6.0.0-rc.4.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for Remote Code Execution (RCE) within the context of the Node.js worker process. Beyond RCE, the ability to control worker environment variables and task scheduling logic permits an attacker to exfiltrate sensitive process information or disrupt application availability. The vulnerability affects any application using an impacted version of Piscina where an upstream prototype pollution primitive exists.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Piscina dependency to version 4.9.4, 5.3.2, or 6.0.0-rc.5 or later.\u003c/li\u003e\n\u003cli\u003eAudit the application codebase for existing prototype pollution vulnerabilities in dependencies, as these are required to trigger this gadget.\u003c/li\u003e\n\u003cli\u003eImplement security scanning to identify vulnerable versions of Piscina (CVE-2026-102992) within the project's dependency manifest.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:20:31Z","date_published":"2026-10-01T20:20:31Z","id":"https://feed.craftedsignal.io/briefs/2026-10-piscina-rce/","summary":"A prototype pollution gadget in the Piscina library allows unauthenticated attackers to execute arbitrary code or manipulate worker environments by injecting properties via Object.prototype.","title":"Prototype Pollution Gadget in Piscina ThreadPool Options","url":"https://feed.craftedsignal.io/briefs/2026-10-piscina-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:piscina_project:piscina:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}