CVE-2026-92941 CRITICAL

CVE-2026-92941: vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation

Vendor Patriksimek
Product vm2
Weakness CWE-732
Published September 17, 2026
Last update September 17, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L

What the vulnerability does

01Description

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.

Key dates

02Disclosure timeline

September 17, 2026 CVE published
September 17, 2026 Record updated