PT-2026-95557 · Cocos Ai · Cocos Ai

CVE-2026-92702

·

Published

2026-09-18

·

Updated

2026-09-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cocos AI versions prior to 0.9.0
Description Cocos AI is a confidential computing system designed for running AI workloads within trusted execution environments. The intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path fails to enforce attestation freshness when the expected reportData value is nil, empty, or omitted. This leaves the SEV-SNP policy ReportData unset, allowing the verifier to accept stale or unrelated Evidence that is not bound to the current connection. Consequently, a relying party using this path without an expected reportData for trust or authorization decisions may be induced to trust an unintended attestation context. If a non-empty reportData is supplied, it remains validated.
Recommendations Update Cocos AI to version 0.9.0.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92702
GHSA-4R6G-MP48-J2RW

Affected Products

Cocos Ai