<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 07:09:03 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-382422</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-382422</link>
      <description>EUVD-2026-382422</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-382422</guid>
    </item>
    <item>
      <title>fkie_cve-2026-104849</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-104849</link>
      <description>&lt;p&gt;Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process&amp;#39;s privileges. This issue is fixed in version 2.1.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker module. Applications are affected only when they pass their own second-argument options object to pool.run(); calls without that argument use the trusted default options object. An attacker who can first pollute the prototype can cause the worker pool to load attacker-selected JavaScript and can read or modify task data with the host process&amp;#39;s privileges. This issue is fixed in version 2.1.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-104849</guid>
    </item>
    <item>
      <title>GHSA-85c8-ppgw-ccpr — Tinypool: Prototype Pollution Gadget to RCE in run() options</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-85c8-ppgw-ccpr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tinypool&lt;/p&gt;
&lt;p&gt;`tinypool` is a fork of `piscina` and inherited the same prototype-pollution surface. When `pool.run(task, options)` is called, the `filename` option is read from the provided `options` object. If that object does not have an own `filename` property, the lookup falls through to `Object.prototype`.&lt;/p&gt;
&lt;p&gt;An attacker who can pollute `Object.prototype.filename` (for example, via a vulnerable `lodash.merge`, `qs.parse`, or similar elsewhere in the application) can make tinypool load and execute an attacker-controlled worker module.&lt;/p&gt;
&lt;p&gt;This is the tinypool counterpart to the piscina root discovery [GHSA-x9g3-xrwr-cwfg](https://github.com/piscinajs/piscina/security/advisories/GHSA-x9g3-xrwr-cwfg).&lt;/p&gt;
&lt;p&gt;`pool.run(task)` with no second argument is not affected, because `kDefaultOptions.filename` is `null` and the options object is not user-controlled. The exploit only triggers when the caller passes their own options object to `pool.run()`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Arbitrary JavaScript execution in the worker pool. If the application passes attacker-controlled data as the `run()` task and also supplies a `run()` options object, the attacker can redirect execution to a malicious worker that exfiltrates or modifies that data, achieving remote code execution and/or data exfiltration.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```js
// legitimate-worker.mjs
export default async (task) =&amp;gt; ({ by: &amp;#39;legitimate-worker&amp;#39;, processed: task })&lt;/p&gt;
&lt;p&gt;// malicious-worker.mjs
export default async (task) =&amp;gt; ({ by: &amp;#39;attacker&amp;#39;, stolenRequestBody: task…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: tinypool&lt;/p&gt;
&lt;p&gt;`tinypool` is a fork of `piscina` and inherited the same prototype-pollution surface. When `pool.run(task, options)` is called, the `filename` option is read from the provided `options` object. If that object does not have an own `filename` property, the lookup falls through to `Object.prototype`.&lt;/p&gt;
&lt;p&gt;An attacker who can pollute `Object.prototype.filename` (for example, via a vulnerable `lodash.merge`, `qs.parse`, or similar elsewhere in the application) can make tinypool load and execute an attacker-controlled worker module.&lt;/p&gt;
&lt;p&gt;This is the tinypool counterpart to the piscina root discovery [GHSA-x9g3-xrwr-cwfg](https://github.com/piscinajs/piscina/security/advisories/GHSA-x9g3-xrwr-cwfg).&lt;/p&gt;
&lt;p&gt;`pool.run(task)` with no second argument is not affected, because `kDefaultOptions.filename` is `null` and the options object is not user-controlled. The exploit only triggers when the caller passes their own options object to `pool.run()`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Arbitrary JavaScript execution in the worker pool. If the application passes attacker-controlled data as the `run()` task and also supplies a `run()` options object, the attacker can redirect execution to a malicious worker that exfiltrates or modifies that data, achieving remote code execution and/or data exfiltration.&lt;/p&gt;
&lt;p&gt;## Proof of Concept&lt;/p&gt;
&lt;p&gt;```js
// legitimate-worker.mjs
export default async (task) =&amp;gt; ({ by: &amp;#39;legitimate-worker&amp;#39;, processed: task })&lt;/p&gt;
&lt;p&gt;// malicious-worker.mjs
export default async (task) =&amp;gt; ({ by: &amp;#39;attacker&amp;#39;, stolenRequestBody: task…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-85c8-ppgw-ccpr</guid>
    </item>
  </channel>
</rss>
