PT-2026-95557 · Cocos Ai · Cocos Ai
CVE-2026-92702
·
Published
2026-09-18
·
Updated
2026-09-30
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cocos AI versions prior to 0.9.0
Description
Cocos AI is a confidential computing system designed for running AI workloads within trusted execution environments. The intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path fails to enforce attestation freshness when the expected
reportData value is nil, empty, or omitted. This leaves the SEV-SNP policy ReportData unset, allowing the verifier to accept stale or unrelated Evidence that is not bound to the current connection. Consequently, a relying party using this path without an expected reportData for trust or authorization decisions may be induced to trust an unintended attestation context. If a non-empty reportData is supplied, it remains validated.Recommendations
Update Cocos AI to version 0.9.0.
Exploit
Fix
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cocos Ai