{"id":"CVE-2026-92702","published":"2026-09-18T18:18:16.257","lastModified":"2026-09-24T21:25:27.050","description":"Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce attestation freshness when the expected reportData value is nil, empty, or omitted, leaving the SEV-SNP policy ReportData unset so the verifier accepts unrelated or stale Evidence not bound to the current connection. A relying party that uses this path without an expected reportData as a trust or authorization decision can be induced to trust an unintended attestation context; a supplied non-empty reportData is still validated. The issue is fixed in version 0.9.0.","cvssScore":9.1,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-346"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ultravioletrs/cocos/commit/80bf813c48300f02259b338b91f844c71be582ea","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/pull/582","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw","tags":[]}],"exploitRefs":[{"url":"https://github.com/ultravioletrs/cocos/commit/80bf813c48300f02259b338b91f844c71be582ea","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/pull/582","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw","tags":[]},{"url":"https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4r6g-mp48-j2rw","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw in Cocos AI allows a relying party to be induced to trust an unintended attestation context due to the lack of attestation freshness enforcement.","exploitability":"Exploitation is moderately hard as it requires the absence of expected reportData and the use of the aTLS AMD SEV-SNP verification path without an expected reportData.","blast_radius":"If exploited, this could lead to unauthorized access or execution of unrelated or stale evidence, compromising the integrity of the trusted execution environment.","remediation":"Upgrade to version 0.9.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["auth-bypass","tls","sev-snp","attribution","trusted-execution"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T09:06:29.610Z"}}