<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 20:21:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-329294</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-329294</link>
      <description>EUVD-2026-329294</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-329294</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55388</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55388</link>
      <description>&lt;p&gt;piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina&amp;#39;s constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller&amp;#39;s options object doesn&amp;#39;t have filename as an own property. When Object.prototype.filename is polluted upstream the inherited value flows to worker_threads.Worker import and the attacker&amp;#39;s .mjs runs in the worker. This vulnerability is fixed in 6.0.0-rc.2, 5.2.0, and 4.9.3.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina&amp;#39;s constructor and run() paths read the filename option via plain member access. Both reads fall through the prototype chain when the caller&amp;#39;s options object doesn&amp;#39;t have filename as an own property. When Object.prototype.filename is polluted upstream the inherited value flows to worker_threads.Worker import and the attacker&amp;#39;s .mjs runs in the worker. This vulnerability is fixed in 6.0.0-rc.2, 5.2.0, and 4.9.3.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55388</guid>
    </item>
    <item>
      <title>GHSA-x9g3-xrwr-cwfg — piscina: Prototype Pollution Gadget → RCE via inherited options.filename</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-x9g3-xrwr-cwfg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: piscina&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`piscina`&amp;#39;s constructor and `run()` paths read the `filename` option via plain member access:&lt;/p&gt;
&lt;p&gt;```js
// dist/index.js line 92 (constructor)
const filename = options.filename
  ? (0, common_1.maybeFileURLToPath)(options.filename)
  : null;
this.options = { ...kDefaultOptions, ...options, filename, maxQueue: 0 };&lt;/p&gt;
&lt;p&gt;// dist/index.js line 616 (run())
run(task, options = kDefaultRunOptions) {
    if (options === null || typeof options !== &amp;#39;object&amp;#39;) {
        return Promise.reject(new TypeError(&amp;#39;options must be an object&amp;#39;));
    }
    const { transferList, filename, name, signal } = options;
```&lt;/p&gt;
&lt;p&gt;Both reads fall through the prototype chain when the caller&amp;#39;s options object doesn&amp;#39;t have `filename` as an own property. When `Object.prototype.filename` is polluted upstream — by any of the well-documented PP-source CVEs (lodash&amp;lt;4.17.13, qs&amp;lt;6.10.3, set-value&amp;lt;4.1.0, minimist&amp;lt;1.2.6, deepmerge&amp;lt;4.2.2, and others) — the inherited value flows to `worker_threads.Worker` import and the attacker&amp;#39;s `.mjs` runs in the worker.&lt;/p&gt;
&lt;p&gt;**Subtlety**: calling `pool.run(task)` with no second arg uses `kDefaultRunOptions` which has `filename: null` as an OWN property — that path DOES NOT fire. The vulnerable shape is when the caller passes their own options object (commonly `{signal: ac.signal}` for abort support, `{name: ...}` for task labelling, etc.). These caller-built options objects inherit from `Object.prototype` unless the caller explicitly uses `Object.create(null)`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Two precondi…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: piscina&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;`piscina`&amp;#39;s constructor and `run()` paths read the `filename` option via plain member access:&lt;/p&gt;
&lt;p&gt;```js
// dist/index.js line 92 (constructor)
const filename = options.filename
  ? (0, common_1.maybeFileURLToPath)(options.filename)
  : null;
this.options = { ...kDefaultOptions, ...options, filename, maxQueue: 0 };&lt;/p&gt;
&lt;p&gt;// dist/index.js line 616 (run())
run(task, options = kDefaultRunOptions) {
    if (options === null || typeof options !== &amp;#39;object&amp;#39;) {
        return Promise.reject(new TypeError(&amp;#39;options must be an object&amp;#39;));
    }
    const { transferList, filename, name, signal } = options;
```&lt;/p&gt;
&lt;p&gt;Both reads fall through the prototype chain when the caller&amp;#39;s options object doesn&amp;#39;t have `filename` as an own property. When `Object.prototype.filename` is polluted upstream — by any of the well-documented PP-source CVEs (lodash&amp;lt;4.17.13, qs&amp;lt;6.10.3, set-value&amp;lt;4.1.0, minimist&amp;lt;1.2.6, deepmerge&amp;lt;4.2.2, and others) — the inherited value flows to `worker_threads.Worker` import and the attacker&amp;#39;s `.mjs` runs in the worker.&lt;/p&gt;
&lt;p&gt;**Subtlety**: calling `pool.run(task)` with no second arg uses `kDefaultRunOptions` which has `filename: null` as an OWN property — that path DOES NOT fire. The vulnerable shape is when the caller passes their own options object (commonly `{signal: ac.signal}` for abort support, `{name: ...}` for task labelling, etc.). These caller-built options objects inherit from `Object.prototype` unless the caller explicitly uses `Object.create(null)`.&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Two precondi…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-x9g3-xrwr-cwfg</guid>
    </item>
  </channel>
</rss>
