kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
High-risk advisory
CVE-2026-55107
Summary
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Why it matters
GitHub has published a reviewed security advisory for kobako. Prioritize it with other application dependency updates.
Operator check
Check whether kobako is present in application dependency manifests, lockfiles, or build images. Review the GitHub advisory and upgrade to a patched version where available.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.