---
id: GHSA-xq74-c7jx-8w5j
title: 'Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store'
summary: 'Duplicate Advisory: vm2 NodeVM can replace the host process TLS trust store'
severity: critical
cvss: 10
cwe:
  - CWE-732
vendor: vm2
product: vm2
ecosystem: npm
affected:
  - 'vm2 >= 3.11.3, <= 3.11.6'
published: '2026-09-17'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:27:12Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-xq74-c7jx-8w5j'
references:
  - url: 'https://github.com/patriksimek/vm2/security/advisories/GHSA-98xx-8mx4-x7cm'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92941'
  - url: >-
      https://www.vulncheck.com/advisories/vm2-3.11.3-before-3.11.7-tls-trust-store-manipulation
  - url: 'https://github.com/advisories/GHSA-xq74-c7jx-8w5j'
tags:
  - ghsa
  - npm
ingestedAt: '2026-10-01T15:48:17.828Z'
---

## Overview

## Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-98xx-8mx4-x7cm. This link is maintained to preserve external references.

## Original Description
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to create host-realm arrays and manipulate the TLS trust store, enabling subsequent host HTTPS clients to accept attacker-controlled certificates.

## Affected packages

- `vm2 >= 3.11.3, <= 3.11.6`

## Remediation

Refer to the advisory for the patched release.
