← Back to search

CVE-2026-92941

10 CRITICALpublic exploit available

Published 2026-09-17 · Updated 2026-09-17

AI risk analysis

Summary
This flaw allows attackers to replace the process-wide certificate authorities in NodeVM sandbox code, enabling them to accept attacker-controlled certificates. This can lead to unauthorized access to secure communications.
Exploitability
Exploitation is relatively straightforward for attackers with access to allowed tls and url builtins. Precondition is access to these builtins.
Blast radius
If exploited, this can result in unauthorized access to sensitive data and services, compromising the security of the entire system.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to vm2 version 3.11.7 or later.
tlscertificatevm2

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Weaknesses

CWE-732

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.