Impact
Piscina's implementation of ThreadPool.options uses a plain object that inherits from Object.prototype. An attacker who can influence the prototype chain can inject values for critical options such as execArgv, loadBalancer, and env. These inherited values are passed directly to the Node.js Worker constructor or used during task scheduling, enabling arbitrary code execution in worker threads. The attacker can preload or execute code that runs with the privileges of the hosting process, compromising confidentiality, integrity, and availability of the entire application.
Affected Systems
The vulnerability affects the piscina Node.js worker pool library, specifically any release prior to v4.9.4, v5.3.2, and v6.0.0-rc.5. Applications that include these older versions of piscina are at risk if they expose ThreadPool.options to user-controlled data or allow prototype pollution in their code paths.
Risk and Exploitability
Piscina's CVSS score of 9.2 reflects a high severity Remote Code Execution risk. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential for exploitation; the vulnerability is exploitably simple once prototype pollution is available. Attackers would need to execute code within the same process that creates the pool, often by injecting malicious values into ThreadPool.options through an existing prototype‑pollution primitive in the application. Once achieved, the attacker can execute arbitrary JavaScript in worker threads and manipulate the worker environment.
OpenCVE Enrichment