{"id":"CVE-2026-92941","published":"2026-09-17T14:17:59.310","lastModified":"2026-09-17T16:18:34.520","description":"vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.","cvssScore":10,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","cwes":["CWE-732"],"vendors":[],"products":[],"references":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm","tags":[]},{"url":"https://www.vulncheck.com/advisories/vm2-3.11.3-before-3.11.7-tls-trust-store-manipulation","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm","tags":[]}],"exploitRefs":[{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm","tags":[]},{"url":"https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm","tags":[]}],"hasPoc":true,"ai":{"summary":"This flaw allows attackers to replace the process-wide certificate authorities in NodeVM sandbox code, enabling them to accept attacker-controlled certificates. This can lead to unauthorized access to secure communications.","exploitability":"Exploitation is relatively straightforward for attackers with access to allowed tls and url builtins. Precondition is access to these builtins.","blast_radius":"If exploited, this can result in unauthorized access to sensitive data and services, compromising the security of the entire system.","remediation":"Upgrade to vm2 version 3.11.7 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["tls","certificate","vm2"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:55:56.794Z"}}