Repository navigation
chore: bump up piscina version to v5.3.2 [SECURITY] - #15681
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Deploying blocksuite-docs with
|
| Latest commit: |
18ed7eb
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://5c8688a3.blocksuite-docs.pages.dev |
| Branch Preview URL: | https://renovate-npm-piscina-vulnera.blocksuite-docs.pages.dev |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## canary #15681 +/- ##
==========================================
- Coverage 54.52% 54.49% -0.03%
==========================================
Files 4022 4022
Lines 192928 192928
Branches 31251 31239 -12
==========================================
- Hits 105188 105136 -52
- Misses 83543 83788 +245
+ Partials 4197 4004 -193
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This PR contains the following updates:
5.2.0→5.3.2piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env
CVE-2026-102992 / GHSA-67c8-pqhq-4rmx
More information
Details
Summary
A prototype-pollution gadget in
ThreadPool.optionsallows an attacker who can polluteObject.prototypeto execute arbitrary code in Piscina worker threads, invoke arbitrary functions during task scheduling, or inject environment variables into workers. The root cause is thatThreadPool.optionsis created as a plain object inheriting fromObject.prototype, so any option without an explicit default inkDefaultOptionscan be supplied via the prototype chain.Details
In
src/index.tstheThreadPoolconstructor builds the resolved options object as a plain object:Because this object has
Object.prototypeas its prototype, reads for properties that are not own properties of the object and are not present inkDefaultOptionsfall back toObject.prototype. This means a prototype-pollution primitive (e.g. from a vulnerablemerge()orJSON.parsemerge elsewhere in the application) can inject values forexecArgv,env,loadBalancer,argv,workerData,resourceLimits,niceIncrement,closeTimeout,recordTiming,stricterFIFO,workerHistogram, andtrackUnmanagedFds.The most serious gadget is
execArgv, which is passed directly tonew Worker(..., { execArgv }). An attacker can setObject.prototype.execArgv = ['--require', '/tmp/attacker.js'], causing every worker to preload and execute the attacker-controlled module on startup.This issue survived the fix for GHSA-x9g3-xrwr-cwfg / CVE-2026-55388 ("Prototype Pollution Gadget → RCE via inherited options.filename"). That advisory hardened the
Piscinaconstructor'sfilenameread andrun()'sfilename/namereads, butThreadPool.optionsitself was not created with a null prototype. The same class of attack is therefore still possible against any option without an explicit default inkDefaultOptions.PoC
/tmp/attacker.jsis executed in the worker on startup. A full reproduction repository withexecArgv,loadBalancer, andenvvectors is available at https://github.com/Fcmam5/piscina-pp-poc.Impact
execArgv(arbitrary--requiremodule preloaded in every worker on spawn).loadBalancer, an attacker-supplied function that is called during task scheduling.env, which is passed to each worker constructor.workerData,resourceLimits,niceIncrement,closeTimeout,recordTiming, etc.Anyone using Piscina in an application where
Object.prototypecan be polluted (e.g. through a dependency with a prototype-pollution vulnerability) is impacted.Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
piscinajs/piscina (piscina)
v5.3.2Compare Source
Full Changelog: piscinajs/piscina@v5.3.1...v5.3.2
v5.3.1Compare Source
What's Changed
Full Changelog: piscinajs/piscina@v5.3.0...v5.3.1
v5.3.0Compare Source
What's Changed
Full Changelog: piscinajs/piscina@v5.2.0...v5.3.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.