Impact
Tinypool constructs thread pool options by copying values from a standard options object before passing them to the Node.js worker_threads.Worker constructor. When this copying is performed without protecting against Object.prototype pollution, an attacker who can inject properties onto Object.prototype can cause malicious execArgv or env values to be copied into the worker options. The attacker can then specify arbitrary JavaScript code to preload via command‑line arguments or NODE_OPTIONS, resulting in execution with the host process’s privileges. This prototype‑pollution flaw directly enables remote code execution.
Affected Systems
The vulnerability affects the tinylibs Tinypool library, specifically all versions prior to 2.1.1. Systems using tinypool 2.1.0 or earlier, regardless of platform, are vulnerable.
Risk and Exploitability
The CVSS score of 9.5 indicates critical severity, and although EPSS is not available, the flaw’s nature and impact suggest a high exploitation likelihood in suitable contexts. The vulnerability is not currently listed in the CISA KEV catalog, but its existence and potential to run arbitrary code make it a high‑risk issue. Attackers would need the ability to influence Object.prototype in the Node.js process that uses tinypool, typically through user‑controlled input or unsanitized data paths, to trigger code execution in the host process.
OpenCVE Enrichment