CVE-2026-55388Active Exploitation

LOWCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller's options object doesn't have filename as an own property. When Object.prototype.filename is polluted upstream the inherited value flows to worker_threads.Worker import and the attacker's .mjs runs in the worker. This vulnerability is fixed in 6.0.0-rc.2, 5.2.0, and 4.9.3.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1321

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-22: 1Active Exploitation · 2026-06-22: 106-22
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting piscina (CVE-2026-55388) https://vuldb.com/vuln/372590/cti

    Post summary

    The CTI team reports multiple activities targeting CVE-2026-55388, indicating ongoing exploitation in the wild, but no PoC, exploit code, patch, or detailed vulnerability information is provided.

    00000104
    2.2K followersView on X

Explore more