
Critical Code Injection Vulnerability Found in Tinypool (CVE-2026-104849) https://www.systemtek.co.uk/2026/10/critical-code-injection-vulnerability-found-in-tinypool-cve-2026-104849/ via @SystemTek_UK
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

Critical Code Injection Vulnerability Found in Tinypool (CVE-2026-104849) https://www.systemtek.co.uk/2026/10/critical-code-injection-vulnerability-found-in-tinypool-cve-2026-104849/ via @SystemTek_UK