OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-55107

CRITICAL · CVSS 10 EPSS 0.80% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Kobako Ruby gem, used for executing untrusted Ruby scripts in a sandboxed environment, is vulnerable to a critical flaw that allows guest mruby scripts to escape the sandbox and execute arbitrary Ruby code in the host process. This vulnerability poses significant risks, including unauthorized access to host resources and potential system compromise. Organizations utilizing Kobako versions prior to 0.9.1 should prioritize patching to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55107
Severity
CRITICAL
CVSS
10
EPSS
0.80%

Original NVD Description

Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.