CyberRota Analysis
AI-GeneratedThe Kobako Ruby gem, used for executing untrusted Ruby scripts in a sandboxed environment, is vulnerable to a critical flaw that allows guest mruby scripts to escape the sandbox and execute arbitrary Ruby code in the host process. This vulnerability poses significant risks, including unauthorized access to host resources and potential system compromise. Organizations utilizing Kobako versions prior to 0.9.1 should prioritize patching to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.