CVE-2026-92941

CRITICAL Status: Deferred

CVSS Scores

CVSS v3.x Base Score
10.0
CRITICAL

Description

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.

Published
September 17, 2026 2:17 PM
Last Modified
September 17, 2026 2:17 PM
Source
[email protected]

Weaknesses (CWE)

CWE-732

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.