Arbitrary Code Execution Vulnerability in Kobako Ruby Gem
CVE-2026-55107

10CRITICAL

Key Information:

Vendor

Elct9620

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-55107?

The Kobako Ruby gem, which integrates a Wasm-isolated mruby interpreter, has a vulnerability that allows guest mruby scripts to execute arbitrary Ruby code within the host process. This means that untrusted scripts, including those generated by LLMs or submitted by users, can bypass the sandbox restrictions and access host resources, raising significant security concerns. This issue affects versions prior to 0.9.1 but has been addressed in the latest release.

Affected Version(s)

kobako >= 0.1.0, < 0.9.1

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.