CVE-2026-92941 Details
Description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.
A vulnerability in vm2 versions 3.11.3 prior to 3.11.7 allows NodeVM sandbox code to access the host TLS module. This exposure enables attackers to call tls.setDefaultCACertificates() and alter process-wide certificate authorities. With access to the allowed tls and url builtins, attackers can manipulate the TLS trust store, causing host HTTPS clients to accept certificates controlled by the attacker.
Users can upgrade to vm2 version 3.11.7 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm | CISA-ADP | AdvisoryExploitRemedyTechnical DescriptionVendor |
| https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm | [email protected] | AdvisoryExploitRemedyTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/vm2-3.11.3-before-3.11.7-tls-trust-store-manipulation | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vm2 | >= 3.11.3, <= 3.11.6 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion