CVE-2026-92941

Source
https://cve.org/CVERecord?id=CVE-2026-92941
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92941.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92941
Aliases
  • GHSA-98xx-8mx4-x7cm
Published
2026-09-17T13:46:04Z
Modified
2026-09-19T03:47:29Z
Severity
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L CVSS Calculator
Summary
vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation
Details

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-732"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92941.json"
}
References

Affected packages

Git / github.com/patriksimek/vm2

Affected ranges

Type
GIT
Repo
https://github.com/patriksimek/vm2
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.11.3"
        },
        {
            "fixed": "3.11.7"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

3.*
3.11.6
v3.*
v3.11.3
v3.11.4
v3.11.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92941.json"