CVE-2026-104849

CVE-2026-104849 published: Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace ...

View full NVD advisory → ← Back to CVE watch