CVE-2026-102992

Source
https://cve.org/CVERecord?id=CVE-2026-102992
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102992.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-102992
Aliases
Downstream
CGA (19)
CLSA (2)
ECHO (1)
MINI (5)
Published
2026-09-30T19:50:18Z
Modified
2026-10-02T03:47:25Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
Details

piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-1321"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102992.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "5.0.0"
                },
                {
                    "fixed":  "5.3.2"
                },
                {
                    "introduced":  "6.0.0-rc.1"
                },
                {
                    "fixed":  "6.0.0-rc.5"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/piscinajs/piscina

Affected ranges

Type
GIT
Repo
https://github.com/piscinajs/piscina
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "4.9.4"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v.*
v.4.9.0
v1.*
v1.0.0
v1.1.0
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.5.0
v1.5.1
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v2.*
v2.0.0
v2.1.0
v2.2.0
v3.*
v3.0.0
v3.1.0
v3.2.0
v4.*
v4.0.0
v4.1.0
v4.2.0
v4.2.1
v4.3.0
v4.3.1
v4.3.2
v4.4.0
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.7.0
v4.8.0
v4.9.1
v4.9.2
v4.9.3
v5.*
v5.0.0
v5.0.0-alpha.0
v5.0.0-alpha.1
v5.0.0-alpha.2
v5.1.0
v5.1.1
v5.1.2
v5.1.3
v5.1.4
v5.2.0
v5.3.0
v5.3.1
v6.*
v6.0.0-rc.0
v6.0.0-rc.2
v6.0.0-rc.3
v6.0.0-rc.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102992.json"