CVE-2026-55107
critical · 10Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
10
CVSS
0.9%
EPSS (exploit prob.)
58th
EPSS percentile
2026-09-30
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-94CWE-470
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-55107