CVE-2026-102992Critical· 9.2▾ AbyssalPoC availablepiscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollu…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 50.6 · likelihood 0 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Exploit / PoC code exists
piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype. Applications with a separate prototype-pollution primitive can therefore supply inherited values for security-sensitive options that do not have own defaults. An inherited execArgv value is passed to the Node.js Worker constructor and can preload attacker-controlled code in worker threads, an inherited loadBalancer function can execute during task scheduling, and inherited env values can alter worker environments. This issue is fixed in versions 4.9.4, 5.3.2, and 6.0.0-rc.5.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-55388High· 8.1piscina: Prototype Pollution Gadget → RCE via inherited options.filename
CVE-2026-101908Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101904Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101900Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-101902Medium· 6.9Axios is a promise-based HTTP client for the browser and Node.js
CVE-2026-97724Medium· 4.3A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePl…