THREAT OPS › Threat News › [GHSA] GHSA-7pwq-q9jf-539h (critical) — kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
[GHSA] GHSA-7pwq-q9jf-539h (critical) — kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
GHSA-7pwq-q9jf-539h Severity: critical CVE: CVE-2026-55107
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
### Summary A guest mruby script running inside the Kobako sandbox can execute arbitrary Ruby in the host process, fully escaping the sandbox.
### Details A host embeds bound "Service" objects that guest scripts call across the wasm b
Indicators of compromise
- CVE-2026-55107cve
Original source: https://github.com/advisories/GHSA-7pwq-q9jf-539h