External risk intelligence

Piscina Node.js Worker Pool Prototype Pollution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-102992

Piscina is a developer-focused Node.js worker pool library used as an internal dependency within applications. It is not an internet-facing service, gateway, or standalone application. The vulnerability requires a secondary prototype-pollution primitive to exploit, making it an internal component-level issue rather than a directly reachable public attack surface.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Piscina, a Node.js worker pool implementation. The issue allows for potential code execution and environment manipulation within worker threads if an application has a separate vulnerability that enables prototype pollution. This could lead to the execution of attacker-controlled code or alteration of worker processes. The main concern is confirming relevance and exposure within your applications.

  • A critical flaw allows attackers to run custom code.
  • Matters if your systems use this specific Node.js tool.
  • Confirm if this library is in use and assess risk.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability if they first gain the ability to perform a prototype pollution attack within an application that uses the affected library. This secondary vulnerability would allow them to manipulate the application's settings for the worker pool, potentially leading to the execution of arbitrary code when new worker threads are created or tasks are scheduled.

  • Requires prior prototype pollution.
  • Vulnerable options are passed to worker.
  • Risk of attacker code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary code within worker threads or alter their environment when supported by a separate prototype-pollution primitive. This could impact service behavior and the integrity of worker processes.

  • Worker thread code execution.
  • Via prototype pollution.
  • Service compromise and behavior alteration.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and infrastructure teams are likely responsible for addressing this vulnerability in the Piscina Node.js worker pool library. The first practical step is to identify all instances of Piscina within your environment, assess their reachability and business criticality, and then locate the accountable team or individual. Once ownership is confirmed, a remediation plan can be developed based on the identified risks.

  • Own by application or platform teams.
  • Verify Piscina's reachability and criticality.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Piscina and how is it used?

Piscina is a specialized library for Node.js that enables applications to run heavy or CPU-intensive tasks across a pool of worker threads. Developers integrate it as a dependency within their applications to manage these background threads efficiently, improving performance by avoiding blockages in the main event loop.

What does CWE-1321 prototype pollution mean for CVE-2026-102992?

This vulnerability is a class of weakness where an application can be tricked into modifying the base behavior of JavaScript objects. Because Piscina stores configuration settings as standard objects, an attacker who successfully triggers prototype pollution can inject malicious values that Piscina then adopts, potentially leading to unauthorized code execution or environment changes.

How does an attacker trigger this vulnerability?

The vulnerability is not triggered by direct interaction with Piscina. It requires a two-step process: first, the attacker must find and exploit a completely separate prototype pollution flaw elsewhere in your application code. If that prerequisite is met, the attacker can then influence Piscina's configuration, which it unknowingly consumes.

Do I need to worry about this if my app is internal?

Halo Surface Signal indicates that Piscina is an internal library rather than a gateway, making it very unlikely to be directly reachable from the internet. However, because it operates deep within your application logic, it still matters for internal security. Assess if your code uses this library and whether it is susceptible to the required prototype pollution.

How do I fix CVE-2026-102992 in my project?

The primary response is to update your project's dependencies to a secure version of Piscina. Specifically, upgrade to versions 4.9.4, 5.3.2, or 6.0.0-rc.5 or later. Once updated, verify that your application has robust defenses against prototype pollution to prevent the underlying trigger mechanism from being exploited.

References