[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-104849":6},{"stargazers_count":4,"fetched_at":5},8,"2026-10-02T17:25:24.142Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":137,"aliases":138,"duplicate_of":9,"upstream":139,"downstream":140,"duplicates":141,"related":142,"reserved_at":9,"published_at":143,"modified_at":143,"state":144,"summary":145,"references_raw":152,"kevs":172,"epss":9,"epss_history":173,"metrics":174,"affected":181},"CVE-2026-104849","Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process's privileges. This issue is fixed in version 2.1.2.",null,[11,62],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-94","Improper Control of Generation of Code ('Code Injection')","The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.","weakness","Draft","Base","Medium",[20,24,58],{"id":21,"name":22,"techniques":23},"CAPEC-242","Code Injection",[],{"id":25,"name":26,"techniques":27},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[28,39,46],{"id":29,"name":30,"tactics":31,"countermeasures":38},"T1027.006","HTML Smuggling",[32,35],{"id":33,"name":34},"TA0030","Defense Evasion",{"id":36,"name":37},"TA0005","Stealth",[],{"id":40,"name":41,"tactics":42,"countermeasures":45},"T1027.009","Embedded Payloads",[43,44],{"id":33,"name":34},{"id":36,"name":37},[],{"id":47,"name":48,"tactics":49,"countermeasures":52},"T1564.009","Resource Forking",[50,51],{"id":33,"name":34},{"id":36,"name":37},[53],{"id":54,"name":55,"tactic":56},"D3-FFV","File Format Verification",{"name":57},"Isolate",{"id":59,"name":60,"techniques":61},"CAPEC-77","Manipulating User-Controlled Variables",[],{"_key":63,"id":63,"name":64,"description":65,"type":15,"status":66,"abstraction":67,"likelihood_of_exploit":9,"capec":68},"CWE-1321","Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')","The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.","Incomplete","Variant",[69,113,135],{"id":70,"name":71,"techniques":72},"CAPEC-1","Accessing Functionality Not Properly Constrained by ACLs",[73],{"id":74,"name":75,"tactics":76,"countermeasures":88},"T1574.010","Services File Permissions Weakness",[77,80,83,84,85],{"id":78,"name":79},"TA0110","Persistence",{"id":81,"name":82},"TA0111","Privilege Escalation",{"id":33,"name":34},{"id":36,"name":37},{"id":86,"name":87},"TA0104","Execution",[89,94,99,104,108],{"id":90,"name":91,"tactic":92},"D3-RS","Restore Software",{"name":93},"Restore",{"id":95,"name":96,"tactic":97},"D3-SWI","Software Inventory",{"name":98},"Model",{"id":100,"name":101,"tactic":102},"D3-SBV","Service Binary Verification",{"name":103},"Detect",{"id":105,"name":106,"tactic":107},"D3-AVE","Asset Vulnerability Enumeration",{"name":98},{"id":109,"name":110,"tactic":111},"D3-SU","Software Update",{"name":112},"Harden",{"id":114,"name":115,"techniques":116},"CAPEC-180","Exploiting Incorrectly Configured Access Control Security Levels",[117],{"id":74,"name":75,"tactics":118,"countermeasures":124},[119,120,121,122,123],{"id":78,"name":79},{"id":81,"name":82},{"id":33,"name":34},{"id":36,"name":37},{"id":86,"name":87},[125,127,129,131,133],{"id":90,"name":91,"tactic":126},{"name":93},{"id":95,"name":96,"tactic":128},{"name":98},{"id":100,"name":101,"tactic":130},{"name":103},{"id":105,"name":106,"tactic":132},{"name":98},{"id":109,"name":110,"tactic":134},{"name":112},{"id":59,"name":60,"techniques":136},[],[],[],[],[],[],[],"2026-10-02T16:17:28.062Z","Deferred",{"cisa_kev":146,"cisa_ransomware":146,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":147,"severity_score":148,"severity_version":149,"severity_source":150,"severity_vector":151,"severity_status":144},false,"critical",9.5,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",[153,159,164,168],{"url":154,"sources":155,"tags":157},"https://github.com/tinylibs/tinypool/security/advisories/GHSA-85c8-ppgw-ccpr",[150,156],"nvd",[158],"X Refsource CONFIRM",{"url":160,"sources":161,"tags":162},"https://github.com/tinylibs/tinypool/pull/135",[150,156],[163],"X Refsource MISC",{"url":165,"sources":166,"tags":167},"https://github.com/tinylibs/tinypool/commit/f41411a3e23324c674f35a19a3240f7a7c40ffbf",[150,156],[163],{"url":169,"sources":170,"tags":171},"https://github.com/tinylibs/tinypool/releases/tag/v2.1.2",[150,156],[163],[],[],[175,178],{"source":150,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":176},{"baseScore":148,"baseSeverity":177,"vectorString":151,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":156,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":179},{"baseScore":148,"baseSeverity":177,"vectorString":180,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",[182],{"ecosystem":9,"name":183,"vendor":184,"product":183,"cpe_part":185,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":186},"tinypool","tinylibs","a",[187],{"version":188,"is_range":189,"range_type":150,"version_start":9,"version_start_type":9,"version_end":190,"version_end_type":191,"fixed_in":9},"\u003C 2.1.2",true,"2.1.2","excluding"]