Description
Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
Published: 2026-09-30
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote code execution in host process
Action: Immediate patch
AI Analysis

Impact

Kobako is a Ruby gem that runs untrusted Ruby scripts within a Wasm-isolated mruby sandbox. The vulnerability allows an attacker to escape this sandbox by exploiting a trigger of method_missing that calls public_send, thereby bypassing the intended isolation. As a result, an attacker can execute arbitrary Ruby code in the host application, giving full control over the process and enabling any actions the process is authorized to perform.

Affected Systems

The affected product is the Kobako Ruby gem from vendor elct9620. All releases from 0.1.0 up to, but not including, version 0.9.1 are vulnerable. Applications that incorporate these versions and accept untrusted Ruby scripts are at risk.

Risk and Exploitability

The CVSS score is 10, indicating critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves delivering malicious Ruby code into the sandbox – for example, a user who can submit scripts, a plugin system, or a developer providing LLM‑generated code. Once the flaw is triggered via method_missing → public_send, the attacker can execute arbitrary Ruby in the host process without restrictions.

Generated by OpenCVE AI on September 30, 2026 at 20:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Kobako to version 0.9.1 or later, which contains the patch for the sandbox escape.
  • If an upgrade is not immediately feasible, disable or remove the feature that accepts user‑supplied Ruby scripts to eliminate the exploitation surface.
  • If upgrading is delayed, ensure that all existing scripts are fully trusted and do not invoke method_missing; consider replacing Kobako with a more secure alternative.

Generated by OpenCVE AI on September 30, 2026 at 20:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-7pwq-q9jf-539h kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
History

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving them access to host memory, files, network, or credentials. From version 0.1.0 to before version 0.9.1, a guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox. This issue has been patched in version 0.9.1.
Title Kobako Vulnerable to Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Weaknesses CWE-470
CWE-94
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-30T19:49:04.193Z

Reserved: 2026-06-16T14:41:54.579Z

Link: CVE-2026-55107

cve-icon Vulnrichment

Updated: 2026-09-30T19:48:41.342Z

cve-icon NVD

Status : Deferred

Published: 2026-09-30T18:18:37.550

Modified: 2026-09-30T20:17:32.923

Link: CVE-2026-55107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:15:05Z

Weaknesses
  • CWE-470

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')