OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-104848

CRITICAL · CVSS 9.5 EPSS 0.50% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Tinypool versions prior to 2.1.1 are vulnerable to a critical code execution flaw due to improper handling of inherited properties from Object.prototype, allowing attackers to inject malicious JavaScript into newly spawned worker threads. This could lead to unauthorized access to sensitive information, including CI secrets and signing materials, with the potential for severe impacts on system integrity. Organizations using affected versions of Tinypool should prioritize upgrading to version 2.1.1 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104848
Severity
CRITICAL
CVSS
9.5
EPSS
0.50%
Java

Original NVD Description

Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.