{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tinypool--2.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:tinypool_project:tinypool:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"id":"CVE-2026-104848"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["tinypool (\u003c= 2.1.0)","tinypool (\u003c 2.1.2)"],"_cs_severities":["critical"],"_cs_tags":["supply-chain","rce","prototype-pollution","javascript"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eTinypool, a worker pool implementation used by high-traffic packages like Vitest, is vulnerable to a prototype pollution attack (CVE-2026-104848) that enables remote code execution. The vulnerability exists because the library explicitly reads worker configuration options (such as 'execArgv' and 'env') from objects that may contain prototype-inherited properties. By polluting 'Object.prototype' with these keys, an attacker can override the library's intended settings. When tinypool spawns a worker thread, it reads these polluted values and passes them as explicit arguments to the Node.js 'worker_threads.Worker' constructor. This re-materialization of inherited properties defeats Node.js core security mechanisms, allowing an attacker to force workers to load arbitrary malicious scripts or inject 'NODE_OPTIONS' into the worker environment. This threat is particularly dangerous in CI/CD pipelines or build environments, where an attacker who gains a prototype-pollution primitive in any dependency can gain execution privileges equivalent to the build host.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a prototype pollution sink in an application dependency (e.g., via a library like lodash or minimist) that allows modifying 'Object.prototype'.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious payload into 'Object.prototype.execArgv' or 'Object.prototype.env'.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a feature in the target application that initializes a new 'Tinypool' instance.\u003c/li\u003e\n\u003cli\u003eTinypool constructor runs, merging 'this.options' via object spread, effectively converting the prototype-inherited properties into own-properties of the configuration object.\u003c/li\u003e\n\u003cli\u003eThe library passes these polluted properties to the internal 'worker_threads.Worker' instantiation logic.\u003c/li\u003e\n\u003cli\u003eNode.js initiates a new worker process utilizing the attacker-supplied '--require' argument or 'NODE_OPTIONS' environment variable.\u003c/li\u003e\n\u003cli\u003eThe worker process executes the attacker's script upon startup with the same permissions as the parent process.\u003c/li\u003e\n\u003cli\u003eAttacker gains full remote code execution within the host environment, potentially accessing secrets, keys, or source code.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows arbitrary code execution with the privileges of the host process. Given tinypool's widespread use as the default worker pool for Vitest (averaging 42 million downloads per week), the primary impact is widespread supply-chain compromise. Attackers can target developer machines or CI/CD runners to exfiltrate environment secrets, steal signing keys, or inject malicious code into build artifacts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of tinypool to a version that implements own-property semantics for worker configuration (ensure the library is patched past version 2.1.0).\u003c/li\u003e\n\u003cli\u003eUse 'Object.create(null)' for configuration object initialization to prevent prototype chain lookups.\u003c/li\u003e\n\u003cli\u003eAudit dependencies for known prototype pollution vulnerabilities using static analysis tools to identify potential source gadgets.\u003c/li\u003e\n\u003cli\u003eImplement runtime protection or monitor for suspicious 'NODE_OPTIONS' or process argument injections in build and test process trees.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T00:42:36Z","date_published":"2026-10-06T00:42:28Z","id":"https://feed.craftedsignal.io/briefs/2026-10-tinypool-rce/","summary":"A prototype pollution vulnerability in the tinypool Node.js worker pool library allows attackers to gain arbitrary code execution in child processes by injecting worker configuration options.","title":"Tinypool Prototype Pollution Leads to Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-10-tinypool-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Tinypool (\u003c= 2.1.0)","version":"https://jsonfeed.org/version/1.1"}