TLS Trust Store Manipulation in vm2 by Patrik Simek
CVE-2026-92941

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92941?

Versions of vm2 earlier than 3.11.7 present a critical vulnerability that exposes the host TLS module to compromised NodeVM sandbox code. This flaw permits an attacker to invoke tls.setDefaultCACertificates(), effectively replacing system-wide certificate authorities. When combined with allowed tls and url builtins, attackers can exploit URLSearchParams to craft host-realm arrays that can manipulate the TLS trust store. This manipulation could lead to the acceptance of maliciously crafted certificates by host HTTPS clients, significantly jeopardizing the security of applications relying on vm2.

Affected Version(s)

vm2 3.11.3 < 3.11.7

vm2 3.11.7

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Forrof
.