Arbitrary Code Execution Vulnerability in Kobako Ruby Gem
CVE-2026-55107
10CRITICAL
What is CVE-2026-55107?
The Kobako Ruby gem, which integrates a Wasm-isolated mruby interpreter, has a vulnerability that allows guest mruby scripts to execute arbitrary Ruby code within the host process. This means that untrusted scripts, including those generated by LLMs or submitted by users, can bypass the sandbox restrictions and access host resources, raising significant security concerns. This issue affects versions prior to 0.9.1 but has been addressed in the latest release.
Affected Version(s)
kobako >= 0.1.0, < 0.9.1
