---
id: CVE-2026-92701
title: >-
  Cocos AI is a confidential computing system for running AI workloads inside
  trusted execution environments
summary: >-
  Cocos AI is a confidential computing system for running AI workloads inside
  trusted execution environments. In versions up to and including 0.8.2, the
  intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy
  the expe…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-346
  - CWE-354
vendor: ultravioletrs
product: cocos
affected:
  - cocos < 0.9.0
published: '2026-09-18'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:25:27.050'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92701'
references:
  - url: 'https://github.com/ultravioletrs/cocos/releases/tag/v0.9.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47
    label: security-advisories@github.com
  - url: >-
      https://github.com/ultravioletrs/cocos/security/advisories/GHSA-4px3-wj2x-xx47
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - exploit-available
  - cve.org
epss: 0.00266
epssPercentile: 0.16421
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/muhammad-usama-sardar/intra-handshake-fail'
  checkedAt: '2026-09-24T21:53:34.704Z'
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-18T19:53:17.098944Z'
ingestedAt: '2026-09-18T17:46:41.553Z'
---

## Overview

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expected current-session freshness value into the TDX quote-body policy before quote validation, so structurally valid TDX QuoteV4 Evidence is accepted without checking that its REPORT_DATA field matches the reportData expected for the current session. A relying party using this path can therefore accept Evidence with a mismatched or reused reportData and release application data after the handshake, enabling session-misbinding to an unintended attestation context. The issue is fixed in version 0.9.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
