Impact
The Prism parser in mruby 4.0.0 contains a NULL pointer dereference (CWE‑476). When a crafted Ruby source file forces the parser to pass a NULL pointer to non‑null string‑handling functions, the resulting undefined behavior terminates the host application, effectively denying service.
Affected Systems
The flaw exists in any build of mruby 4.0.0. Any software that links against that specific source tree, regardless of platform, can be impacted if it exposes the Prism parser to user‑supplied Ruby code. No specific vendor or product names are supplied, and the issue is not tied to a commercial distribution.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to provide crafted Ruby code that is parsed by the Prism component, so the attack surface is limited to applications that dynamically execute user‑supplied Ruby. Based on the description, it is inferred that the attack vector is local execution of malicious Ruby source files; because no public exploit code exists, the overall risk remains moderate.
OpenCVE Enrichment