๐Ÿ” CVE Alert

CVE-2026-55107

CRITICAL 10.0

Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing โ†’ public_send (any bound Service)

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.

CWE CWE-94 CWE-470
Vendor elct9620
Product kobako
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for elct9620 kobako

Be the first to know when new critical vulnerabilities affecting elct9620 kobako are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

elct9620 / kobako
>= 0.1.0, < 0.9.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/elct9620/kobako/security/advisories/GHSA-7pwq-q9jf-539h github.com: https://github.com/elct9620/kobako/commit/64f84700c81f44902bed9211318d5362f44987b3 github.com: https://github.com/elct9620/kobako/releases/tag/v0.9.1