Get real-time updates on Telegram
P5Verified
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution
CVE-2026-104848 affects tinypool. EPSS 0.00497 (percentile 0.4044), scored 2026-10-04. Affected range: <= 2.1.0. Fixed version: 2.1.1.
- CVE
- CVE-2026-104848
- Product
- tinypool
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00497 · percentile 0.4044 · 2026-10-04
- KEV
- no
Affected products
- tinypool · <= 2.1.0 · Fixed version: 2.1.1
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-05 23:10:51.172112+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-104848.html