CVE-2026-55388

Description

A flaw was found in piscina, a Node.js worker pool implementation. This vulnerability allows an attacker to achieve arbitrary code execution by exploiting a prototype pollution issue. By manipulating the filename option, an attacker can cause their malicious code to be executed within the worker, potentially compromising the system's confidentiality, integrity, and availability.

Statement

This is an Important flaw due to arbitrary code execution via prototype pollution. Red Hat products are not affected by this vulnerability as the vulnerable code is not present in Red Hat's piscina implementation.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

An attacker could modify sensitive data or program variables.

Integrity

Technical Impact: Execute Unauthorized Code or Commands

Other,Integrity

Technical Impact: Varies by Context; Alter Execution Logic

Frequently Asked Questions

Want to get errata notifications? Sign up here.