Product
A prototype pollution vulnerability in the tinypool Node.js worker pool library allows attackers to gain arbitrary code execution in child processes by injecting worker configuration options.