Impact
Kobako is a Ruby gem that runs untrusted Ruby scripts within a Wasm-isolated mruby sandbox. The vulnerability allows an attacker to escape this sandbox by exploiting a trigger of method_missing that calls public_send, thereby bypassing the intended isolation. As a result, an attacker can execute arbitrary Ruby code in the host application, giving full control over the process and enabling any actions the process is authorized to perform.
Affected Systems
The affected product is the Kobako Ruby gem from vendor elct9620. All releases from 0.1.0 up to, but not including, version 0.9.1 are vulnerable. Applications that incorporate these versions and accept untrusted Ruby scripts are at risk.
Risk and Exploitability
The CVSS score is 10, indicating critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves delivering malicious Ruby code into the sandbox – for example, a user who can submit scripts, a plugin system, or a developer providing LLM‑generated code. Once the flaw is triggered via method_missing → public_send, the attacker can execute arbitrary Ruby in the host process without restrictions.
OpenCVE Enrichment
Github GHSA