← All CVEs

CVE-2026-55107

critical · 10

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.

10
CVSS
0.9%
EPSS (exploit prob.)
58th
EPSS percentile
2026-09-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-94CWE-470

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-55107