{"id":"CVE-2026-92701","published":"2026-09-18T18:18:16.103","lastModified":"2026-09-24T21:25:27.050","description":"Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-346","CWE-354"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47","tags":[]}],"exploitRefs":[{"url":"https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw in Cocos AI allows a relying party to accept a TDX QuoteV4 Evidence with mismatched or reused reportData, enabling session-misbinding and potential unauthorized access to application data.","exploitability":"Exploitation requires control over the TLS handshake process and knowledge of the affected TDX version. Precondition is access to the TLS communication path.","blast_radius":"If exploited, this could lead to unauthorized access to sensitive application data within the trusted execution environment.","remediation":"Upgrade to Cocos AI version 0.9.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","tls","tdx","attestation","trusted-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:06:35.570Z"}}