Medium · 5.9 Node.js & npm GHSA-67c8-pqhq-4rmx CVE-2026-102992
Piscina Worker Pool: Prototype-Pollution Gadget Can Lead to Code Execution (CVE-2026-102992)
Piscina, a Node.js worker pool library, stores its ThreadPool options as a plain object inheriting from Object.prototype. Combined with a separate prototype-pollution bug elsewhere in an application, this can let an attacker influence security-sensitive worker settings such as execArgv, loadBalancer, or env, potentially leading to code execution in worker threads. Fixed in 4.9.4, 5.3.2, and 6.0.0-rc.5.
AI summary
A vulnerability has been disclosed in piscina, a Node.js worker pool implementation used to run tasks in worker threads. Tracked as CVE-2026-102992 (GHSA-67c8-pqhq-4rmx), the issue concerns how piscina stores its internal configuration object, which can be abused in combination with a prototype-pollution flaw elsewhere in an application to influence security-sensitive worker settings. Fixed versions are available.
What happened
Piscina stores the ThreadPool.options object as a plain JavaScript object in src/index.ts, meaning it inherits properties from Object.prototype rather than using a null-prototype or otherwise isolated object. If an application using piscina has a separate prototype-pollution primitive (a different vulnerability that lets an attacker set arbitrary properties on Object.prototype), that primitive can supply inherited values for piscina options that do not have their own explicit defaults.
Technical cause
Because ThreadPool.options is a plain object, three security-sensitive options are reachable via prototype inheritance when no own value is set: execArgv, which is passed directly to the Node.js Worker constructor and can be used to preload attacker-controlled code into worker threads; loadBalancer, a function that executes during task scheduling and can therefore run attacker-supplied logic; and env, which can alter the environment variables available to worker threads. This is classified as CWE-1321, Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution').
Why it matters
On its own, this issue in piscina is a gadget rather than a standalone exploit: it requires a separate prototype-pollution vulnerability elsewhere in the application to be present and reachable by an attacker. However, when that precondition is met, the impact is severe, since influencing execArgv or loadBalancer can lead to execution of attacker-controlled code in worker threads. The CVSS 4.0 base score of 9.2 reflects this high potential impact on confidentiality, integrity, and availability once the gadget is triggered.
Affected versions
Piscina versions before 4.9.4 are affected. Versions from 5.0.0 up to (but not including) 5.3.2 are affected. Pre-release versions from 6.0.0-rc.1 up to (but not including) 6.0.0-rc.5 are also affected.
Fixes and mitigation
The issue is fixed in piscina versions 4.9.4, 5.3.2, and 6.0.0-rc.5. Applications should update to one of these fixed versions. Note that this gadget is only exploitable in combination with a separate prototype-pollution vulnerability elsewhere in the application; eliminating any such pollution primitives in application code is also an important mitigating step, independent of the piscina update.
Recommended action
Update piscina to version 4.9.4, 5.3.2, or 6.0.0-rc.5 depending on your current release line. Additionally, audit your application and its dependencies for other prototype-pollution vulnerabilities, since this piscina issue by itself requires such a primitive elsewhere to be exploitable.
PatchBriefing score
5.9 / 10 · Medium
Official CVSS: 9.2
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Why this score
Patchwire assigned a score of 5.9. This reflects a high CVSS 4.0 base score of 9.2, driven by the severe potential impact (confidentiality, integrity, and availability) if the gadget is triggered via an unauthenticated, no-interaction attack path once a prototype-pollution primitive exists elsewhere in the application. The score also factors in that the vulnerability requires no user interaction and no authentication to exploit the gadget itself. No EPSS score, known exploitation, or public exploit code has been reported, and a fix is already available, which moderates the overall score relative to the raw CVSS value.
Affected versions
- piscina >= 6.0.0-rc.1, < 6.0.0-rc.5
- vulnerable
- ≥ 4.9.4
- patched
- ≥ 5.3.2
- patched
- ≥ 6.0.0-rc.5
- patched
Reported fixes
The issue is fixed in piscina versions 4.9.4, 5.3.2, and 6.0.0-rc.5. Applications should update to one of these fixed versions. Note that this gadget is only exploitable in combination with a separate prototype-pollution vulnerability elsewhere in the application; eliminating any such pollution primitives in application code is also an important mitigating step, independent of the piscina update.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email