CVE-2026-55107
Received Received - Intake

Code Execution Escape in Kobako Ruby Gem

Vulnerability report for CVE-2026-55107, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: GitHub, Inc.

Description

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elct9620 kobako to 0.9.1 (exc)
elct9620 kobako 0.9.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CWE-470 The product uses external input with reflection to select which classes or code to use, but it does not sufficiently prevent the input from selecting improper classes or code.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-55107 is a critical sandbox escape vulnerability in the Kobako Ruby gem. It allows a guest mruby script running inside the sandbox to execute arbitrary Ruby code in the host process, fully bypassing the intended isolation. The issue occurs because the dispatcher uses Object#public_send to invoke methods without restrictions, enabling attackers to call dangerous Kernel methods like eval via reflection.

Detection Guidance

Check if your Kobako gem version is between 0.1.0 and 0.9.0 using the command 'gem list kobako'. If installed, verify the version with 'bundle list | grep kobako'. Vulnerable versions lack method allowlist restrictions in the dispatcher.

Impact Analysis

This vulnerability allows an attacker to execute arbitrary code on the host system, leading to full remote code execution (RCE). This could result in complete system compromise, data theft, unauthorized access, or further network infiltration if the host process has elevated privileges.

Mitigation Strategies

Upgrade Kobako to version 0.9.1 or later immediately using 'gem install kobako -v 0.9.1' or update your Gemfile. No workarounds exist for affected versions; patching is required to prevent sandbox escape and RCE.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55107. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart