Description
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.
Published: 2026-09-30
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Piscina's implementation of ThreadPool.options uses a plain object that inherits from Object.prototype. An attacker who can influence the prototype chain can inject values for critical options such as execArgv, loadBalancer, and env. These inherited values are passed directly to the Node.js Worker constructor or used during task scheduling, enabling arbitrary code execution in worker threads. The attacker can preload or execute code that runs with the privileges of the hosting process, compromising confidentiality, integrity, and availability of the entire application.

Affected Systems

The vulnerability affects the piscina Node.js worker pool library, specifically any release prior to v4.9.4, v5.3.2, and v6.0.0-rc.5. Applications that include these older versions of piscina are at risk if they expose ThreadPool.options to user-controlled data or allow prototype pollution in their code paths.

Risk and Exploitability

Piscina's CVSS score of 9.2 reflects a high severity Remote Code Execution risk. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential for exploitation; the vulnerability is exploitably simple once prototype pollution is available. Attackers would need to execute code within the same process that creates the pool, often by injecting malicious values into ThreadPool.options through an existing prototype‑pollution primitive in the application. Once achieved, the attacker can execute arbitrary JavaScript in worker threads and manipulate the worker environment.

Generated by OpenCVE AI on September 30, 2026 at 22:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Piscina to version 4.9.4, 5.3.2, or 6.0.0-rc.5 or later, which removes the prototype‑pollution window for ThreadPool.options.
  • Validate and sanitize all inputs that are used to construct or modify ThreadPool.options, ensuring that no untrusted data can influence the prototype chain.
  • If upgrading is not immediately possible, restrict the Node.js worker’s execArgv, loadBalancer, and env options to safe defaults or disable them entirely to reduce the attack surface.

Generated by OpenCVE AI on September 30, 2026 at 22:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.
Title piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T20:47:49.562Z

Reserved: 2026-09-29T20:46:08.334Z

Link: CVE-2026-102992

cve-icon Vulnrichment

Updated: 2026-09-30T20:47:44.299Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T20:17:27.080

Modified: 2026-09-30T21:17:06.450

Link: CVE-2026-102992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T22:45:16Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')