CVE-2026-92941
10 CRITICALpublic exploit availablePublished 2026-09-17 · Updated 2026-09-17
AI risk analysis
- Summary
- This flaw allows attackers to replace the process-wide certificate authorities in NodeVM sandbox code, enabling them to accept attacker-controlled certificates. This can lead to unauthorized access to secure communications.
- Exploitability
- Exploitation is relatively straightforward for attackers with access to allowed tls and url builtins. Precondition is access to these builtins.
- Blast radius
- If exploited, this can result in unauthorized access to sensitive data and services, compromising the security of the entire system.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to vm2 version 3.11.7 or later.
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Weaknesses
CWE-732
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2026-18753
- CRITICALCVE-2026-18754
- HIGHCVE-2026-54876PoC
- CRITICALCVE-2026-61550PoC
- HIGHCVE-2026-80110
- CRITICALCVE-2026-86246
- MEDIUMCVE-2026-91166PoC
- CRITICALCVE-2026-92701PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.