TLS Trust Store Manipulation in vm2 by Patrik Simek
CVE-2026-92941
10CRITICAL
What is CVE-2026-92941?
Versions of vm2 earlier than 3.11.7 present a critical vulnerability that exposes the host TLS module to compromised NodeVM sandbox code. This flaw permits an attacker to invoke tls.setDefaultCACertificates(), effectively replacing system-wide certificate authorities. When combined with allowed tls and url builtins, attackers can exploit URLSearchParams to craft host-realm arrays that can manipulate the TLS trust store. This manipulation could lead to the acceptance of maliciously crafted certificates by host HTTPS clients, significantly jeopardizing the security of applications relying on vm2.
Affected Version(s)
vm2 3.11.3 < 3.11.7
vm2 3.11.7
