piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
Published Sep 30, 2026
9.2
CRITICALCVSS 4.0
EPSS 0.55%
Description
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.
Affected products
-
- Version < 4.9.4StatusaffectedConstraints-
- Version >= 5.0.0, < 5.3.2StatusaffectedConstraints-
- Version >= 6.0.0-rc.1, < 6.0.0-rc.5StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
piscina
npm
Introduced 5.0.0 Fixed 5.3.2piscina
npm
Introduced 0 Fixed 4.9.4piscina
npm
Introduced 6.0.0-rc.1 Fixed 6.0.0-rc.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | piscina | 5.0.0 | 5.3.2 |
| npm | piscina | 0 | 4.9.4 |
| npm | piscina | 6.0.0-rc.1 | 6.0.0-rc.5 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (10)
- https://github.com/advisories/GHSA-67c8-pqhq-4rmx Advisory
- https://github.com/piscinajs/piscina/commit/0cb12fca37f526065b072592afe954574dcc656f x_refsource_MISC
- https://github.com/piscinajs/piscina/commit/2f69f67159a0e48b38fd61fa4a91c2fdc19fff72 x_refsource_MISC
- https://github.com/piscinajs/piscina/commit/5be7bbb19e3787bb698862cd516121a578d690f7 x_refsource_MISC
- https://github.com/piscinajs/piscina/commit/bebbda255c2981cecddd36b171b94be2fd41c9a6 x_refsource_MISC
- https://github.com/piscinajs/piscina/releases/tag/v4.9.4 x_refsource_MISC
- https://github.com/piscinajs/piscina/releases/tag/v5.3.2 x_refsource_MISC
- https://github.com/piscinajs/piscina/releases/tag/v6.0.0-rc.5 x_refsource_MISC
- https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx exploitx_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102992
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-67c8-pqhq-4rmx | Advisory | |
| https://github.com/piscinajs/piscina/commit/0cb12fca37f526065b072592afe954574dcc656f | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/commit/2f69f67159a0e48b38fd61fa4a91c2fdc19fff72 | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/commit/5be7bbb19e3787bb698862cd516121a578d690f7 | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/commit/bebbda255c2981cecddd36b171b94be2fd41c9a6 | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/releases/tag/v4.9.4 | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/releases/tag/v5.3.2 | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/releases/tag/v6.0.0-rc.5 | x_refsource_MISC | |
| https://github.com/piscinajs/piscina/security/advisories/GHSA-67c8-pqhq-4rmx | exploitx_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102992 |
Change history (0)
No recorded changes yet.