CVE-2026-102992
Deferred Deferred - Pending Action

Prototype Pollution in Piscina Worker Pool

Vulnerability report for CVE-2026-102992, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1321 The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a prototype pollution issue in the Piscina Node.js worker pool library. Prior to versions 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stored ThreadPool.options as a plain object inheriting from Object.prototype. Attackers with prototype pollution capabilities could inject malicious values into security-sensitive options like execArgv, loadBalancer, or env. These values could then be used to execute arbitrary code in worker threads, manipulate task scheduling, or alter worker environments.

Detection Guidance

Detecting this vulnerability requires checking if your system uses a vulnerable version of Piscina (4.x, 5.x, or 6.0.0-rc.x). Run: npm list piscina. If the version is below 4.9.4, 5.3.2, or 6.0.0-rc.5, the system is vulnerable. Additionally, check for prototype pollution in dependencies by auditing with npm audit or running: npm ls --all to inspect dependency chains.

Impact Analysis

If you use a vulnerable version of Piscina in your application, attackers could exploit this to execute arbitrary code on your system through worker threads. They could also manipulate task scheduling via loadBalancer or modify environment variables in worker processes. This could lead to data breaches, system compromise, or denial of service if the attacker disrupts worker operations.

Compliance Impact

This vulnerability could lead to unauthorized code execution or data access, violating GDPR's integrity and confidentiality requirements or HIPAA's security rules for protected health information. A successful exploit might result in data exfiltration or system compromise, both of which would constitute compliance violations requiring breach notifications under these regulations.

Mitigation Strategies

Upgrade Piscina to a patched version (4.9.4, 5.3.2, or 6.0.0-rc.5 or later) immediately. Use: npm update piscina. If upgrading is not possible, implement runtime checks to validate pool.options properties and sanitize inputs to prevent prototype pollution. Review third-party dependencies for similar vulnerabilities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102992. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart