<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:piscina_project:piscina:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apiscina_projectpiscinanode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 20:20:31 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apiscina_projectpiscinanode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Prototype Pollution Gadget in Piscina ThreadPool Options</title><link>https://feed.craftedsignal.io/briefs/2026-10-piscina-rce/</link><pubDate>Thu, 01 Oct 2026 20:20:31 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-piscina-rce/</guid><description>A prototype pollution gadget in the Piscina library allows unauthenticated attackers to execute arbitrary code or manipulate worker environments by injecting properties via Object.prototype.</description><content:encoded><![CDATA[<p>Piscina, a popular Node.js worker pool library, is vulnerable to a prototype pollution gadget that enables remote code execution (RCE) and environment manipulation. The vulnerability (CVE-2026-102992) stems from how the <code>ThreadPool</code> class constructs its internal options object. By using object spread syntax (<code>{ ...kDefaultOptions, ...options }</code>) on a plain object that inherits from <code>Object.prototype</code>, Piscina inadvertently honors properties present in the global prototype if they are not explicitly defined in the options provided to the constructor.</p>
<p>An attacker who can influence the application state to pollute <code>Object.prototype</code> can inject malicious configuration values. The most critical vector is the <code>execArgv</code> property, which allows an attacker to force worker threads to load an arbitrary module via the <code>--require</code> flag upon initialization. Other vectors include the <code>loadBalancer</code> function, which can be manipulated to execute arbitrary logic during task scheduling, and the <code>env</code> property, which allows for the injection of environment variables into worker processes. This issue persists in Piscina versions &lt; 4.9.4, 5.0.0 through 5.3.1, and 6.0.0-rc.1 through 6.0.0-rc.4.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for Remote Code Execution (RCE) within the context of the Node.js worker process. Beyond RCE, the ability to control worker environment variables and task scheduling logic permits an attacker to exfiltrate sensitive process information or disrupt application availability. The vulnerability affects any application using an impacted version of Piscina where an upstream prototype pollution primitive exists.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the Piscina dependency to version 4.9.4, 5.3.2, or 6.0.0-rc.5 or later.</li>
<li>Audit the application codebase for existing prototype pollution vulnerabilities in dependencies, as these are required to trigger this gadget.</li>
<li>Implement security scanning to identify vulnerable versions of Piscina (CVE-2026-102992) within the project's dependency manifest.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>prototype-pollution</category><category>supply-chain</category></item></channel></rss>