Critical vulnerabilities discovered in the Tinypool package expose environments to severe exploitation risks through prototype pollution gadgets. The flaws exist within the parameter handling mechanisms of worker and function execution routines, allowing unauthorized modification of base object properties. Attackers leveraging these weaknesses can bypass input sanitization boundaries and inject arbitrary properties into the global Object prototype. This manipulation leads directly to remote code execution within the context of the hosting process, threatening data confidentiality, system integrity, and service availability. Organizations utilizing impacted versions face severe compromise vectors if untrusted input is processed through worker options.
CVE-2026-104849:A prototype pollution vulnerability exists within the option parsing logic of the run execution function in Tinypool. Input containing malicious payload properties alters standard object attributes, allowing an unauthenticated attacker to manipulate execution behavior. Successful exploitation allows arbitrary code execution on the underlying host system, leading to complete control over application functionality and potential unauthorized access to sensitive application data.[/subscribe_to_unlock_form]
Critical vulnerabilities discovered in the Tinypool package expose environments to severe exploitation risks through prototype pollution gadgets. The flaws exist within the parameter handling mechanisms of worker and function execution routines, allowing unauthorized modification of base object properties. Attackers leveraging these weaknesses can bypass input sanitization boundaries and inject arbitrary properties into the global Object prototype. This manipulation leads directly to remote code execution within the context of the hosting process, threatening data confidentiality, system integrity, and service availability. Organizations utilizing impacted versions face severe compromise vectors if untrusted input is processed through worker options.
CVE-2026-104849:A prototype pollution vulnerability exists within the option parsing logic of the run execution function in Tinypool. Input containing malicious payload properties alters standard object attributes, allowing an unauthenticated attacker to manipulate execution behavior. Successful exploitation allows arbitrary code execution on the underlying host system, leading to complete control over application functionality and potential unauthorized access to sensitive application data.[emaillocker id="1283"]
CVE-2026-104848:A critical prototype pollution gadget in the worker configuration options allows attackers to pollute global object properties during worker initialization. By passing crafted configuration objects to the pool initialization routines, an attacker can manipulate core runtime behaviors. This flaw directly enables remote code execution within the worker process environment, exposing internal services to severe system-level compromise and potential lateral movement.
Immediate remediation is strongly recommended to prevent potential exploitation and safeguard infrastructure against remote compromise. Applying available updates to patched library releases effectively mitigates these prototype pollution vectors and ensures secure worker execution dynamics.
We recommend you to update tinypool to version 2.1.2.
The following reports contain further technical details:
[/emaillocker]