Impact
The flaw occurs when the OP_SUPER instruction is executed without a guard for a top‑level super pointer in the mrubyc virtual machine. The missing runtime check allows a crafted input to dereference a null pointer, causing the process to crash or potentially corrupt memory, as identified by CWE‑476.
Affected Systems
All releases of mrubyc up to and including version 3.4.1 are affected. The flaw exists in the open‑source code distributed through the project’s repository and will impact any environment that incorporates these versions.
Risk and Exploitability
The CVSS score of 7.5 classifies the vulnerability as high severity, but the EPSS score of less than 1% suggests a low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is inferred to be local or remote, depending on whether an attacker can execute a malicious mrubyc script against the target application; specific prerequisites and detailed exploitation steps are not provided in the advisory.
OpenCVE Enrichment