CyberRota Analysis
AI-GeneratedTinypool versions prior to 2.1.1 are vulnerable to a critical code execution flaw due to improper handling of inherited properties from Object.prototype, allowing attackers to inject malicious JavaScript into newly spawned worker threads. This could lead to unauthorized access to sensitive information, including CI secrets and signing materials, with the potential for severe impacts on system integrity. Organizations using affected versions of Tinypool should prioritize upgrading to version 2.1.1 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be copied into own properties and passed to worker_threads.Worker. An attacker who can first pollute either property can cause each newly spawned worker to load attacker-selected JavaScript through command-line preload arguments or NODE_OPTIONS, resulting in code execution with the host process's privileges and possible access to CI secrets, signing material, or build artifacts. This issue is fixed in version 2.1.1.