Skip to content

chore: bump up piscina version to v5.3.2 [SECURITY] - #15681

Merged
darkskygit merged 2 commits into
canaryfrom
renovate/npm-piscina-vulnerability
Oct 7, 2026
Merged

darkskygit merged 2 commits into
canaryfrom
renovate/npm-piscina-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
piscina 5.2.0 → 5.3.2 age confidence

piscina: Prototype-pollution gadget in ThreadPool.options allows RCE via execArgv / loadBalancer / env

CVE-2026-102992 / GHSA-67c8-pqhq-4rmx

More information

Details

Summary

A prototype-pollution gadget in ThreadPool.options allows an attacker who can pollute Object.prototype to execute arbitrary code in Piscina worker threads, invoke arbitrary functions during task scheduling, or inject environment variables into workers. The root cause is that ThreadPool.options is created as a plain object inheriting from Object.prototype, so any option without an explicit default in kDefaultOptions can be supplied via the prototype chain.

Details

In src/index.ts the ThreadPool constructor builds the resolved options object as a plain object:

this.options = { ...kDefaultOptions, ...options, filename, maxQueue: 0 }

Because this object has Object.prototype as its prototype, reads for properties that are not own properties of the object and are not present in kDefaultOptions fall back to Object.prototype. This means a prototype-pollution primitive (e.g. from a vulnerable merge() or JSON.parse merge elsewhere in the application) can inject values for execArgv, env, loadBalancer, argv, workerData, resourceLimits, niceIncrement, closeTimeout, recordTiming, stricterFIFO, workerHistogram, and trackUnmanagedFds.

The most serious gadget is execArgv, which is passed directly to new Worker(..., { execArgv }). An attacker can set Object.prototype.execArgv = ['--require', '/tmp/attacker.js'], causing every worker to preload and execute the attacker-controlled module on startup.

This issue survived the fix for GHSA-x9g3-xrwr-cwfg / CVE-2026-55388 ("Prototype Pollution Gadget → RCE via inherited options.filename"). That advisory hardened the Piscina constructor's filename read and run()'s filename/name reads, but ThreadPool.options itself was not created with a null prototype. The same class of attack is therefore still possible against any option without an explicit default in kDefaultOptions.

PoC
import { resolve } from 'node:path'
import Piscina from 'piscina'

Object.prototype.execArgv = ['--require', '/tmp/attacker.js']

const pool = new Piscina({
  filename: resolve(import.meta.dirname, 'worker.js'),
  minThreads: 1,
  maxThreads: 1,
})

await pool.run(1)

/tmp/attacker.js is executed in the worker on startup. A full reproduction repository with execArgv, loadBalancer, and env vectors is available at https://github.com/Fcmam5/piscina-pp-poc.

Impact
  • Remote Code Execution: via execArgv (arbitrary --require module preloaded in every worker on spawn).
  • Arbitrary code execution in the main thread: via loadBalancer, an attacker-supplied function that is called during task scheduling.
  • Environment/CLI option injection: via env, which is passed to each worker constructor.
  • Denial of Service / unexpected behavior: via other reachable options such as workerData, resourceLimits, niceIncrement, closeTimeout, recordTiming, etc.

Anyone using Piscina in an application where Object.prototype can be polluted (e.g. through a dependency with a prototype-pollution vulnerability) is impacted.

Severity

  • CVSS Score: 9.2 / 10 (Critical)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

piscinajs/piscina (piscina)

v5.3.2

Compare Source

Full Changelog: piscinajs/piscina@v5.3.1...v5.3.2

v5.3.1

Compare Source

What's Changed

Full Changelog: piscinajs/piscina@v5.3.0...v5.3.1

v5.3.0

Compare Source

What's Changed

Full Changelog: piscinajs/piscina@v5.2.0...v5.3.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Oct 6, 2026
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ac234517-23c7-417b-ae99-57522badc7a6

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying blocksuite-docs with  Cloudflare Pages  Cloudflare Pages

Latest commit: 18ed7eb
Status: ✅  Deploy successful!
Preview URL: https://5c8688a3.blocksuite-docs.pages.dev
Branch Preview URL: https://renovate-npm-piscina-vulnera.blocksuite-docs.pages.dev

View logs

@codecov

codecov Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 54.49%. Comparing base (21390ce) to head (cdddff3).
⚠️ Report is 7 commits behind head on canary.

Additional details and impacted files
@@            Coverage Diff             @@
##           canary   #15681      +/-   ##
==========================================
- Coverage   54.52%   54.49%   -0.03%     
==========================================
  Files        4022     4022              
  Lines      192928   192928              
  Branches    31251    31239      -12     
==========================================
- Hits       105188   105136      -52     
- Misses      83543    83788     +245     
+ Partials     4197     4004     -193     
Flag Coverage Δ
server-test 78.14% <ø> (-0.05%) ⬇️
unittest 33.82% <ø> (-0.03%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@darkskygit
darkskygit merged commit 6bb6457 into canary Oct 7, 2026
33 of 34 checks passed
@darkskygit
darkskygit deleted the renovate/npm-piscina-vulnerability branch October 7, 2026 02:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

1 participant