Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104849— Tinypool: Prototype Pollution Gadget to RCE in run() options

Quick assessment

Affected
tinylibs tinypool
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tinypool 是一个极简的 Node.js 工作线程池实现。在 2.1.2 版本之前,Tinypool 在调用 时,会从调用者提供的 options 对象中直接读取 filename 属性,而未进行自有属性(own property)检查。因此,如果攻击者污染了 ,就可以替换预期的工作模块。只有当应用向 传入自定义的第二参数 options 对象时,应用才会受到该漏洞影响;不带该参数的调用会使用可信的默认 options 对象。能够首先污染原型的攻击者可以导致工作线程池加载由攻击者指定的 JavaScript

CVSS 9.5 · Critical

Affected Version Matrix 1

VendorProduct Version RangeStatus
tinylibs tinypool < 2.1.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104849

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tinypool: Prototype Pollution Gadget to RCE in run() options
Source: CVE Program / CVE List V5
Vulnerability Description
Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tinylibs tinypool < 2.1.2 -

II. Public POCs for CVE-2026-104849

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104849

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104849 (2)

Vendor Advisories for CVE-2026-104849 (1)

Other References for CVE-2026-104849 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104849

No comments yet


Leave a comment