Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 17 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates. | |
| Title | vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T15:48:59.103Z
Reserved: 2026-09-17T12:42:34.828Z
Link: CVE-2026-92941
Updated: 2026-09-17T15:48:51.299Z
Status : Deferred
Published: 2026-09-17T14:17:59.310
Modified: 2026-09-17T16:18:34.520
Link: CVE-2026-92941
No data.
OpenCVE Enrichment
No data.
-
CWE-732
Incorrect Permission Assignment for Critical Resource