CVE-2026-102992 - piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
CVE ID :CVE-2026-102992 Published : Sept. 30, 2026, 8:17 p.m. | 22 minutes ago Description :piscina is a node.js worker pool implementation. Prior to 4.9.4, 5.3.2, and 6.0.0-rc.5, Piscina stores ThreadPool.options in src/index.ts as a plain object that inherits from Object.prototype....