{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/execute_ruby-1.4.0-to-1.6.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.4,"id":"CVE-2026-81097"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["execute_ruby (1.4.0 to 1.6.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe execute_ruby tool, designed as a read-only Ruby sandbox, contains a critical security vulnerability (CVE-2026-81097) in versions 1.4.0 through 1.6.0. The sandbox relies on a pattern-based denylist and method overriding for Kernel process-spawning functions to maintain isolation. However, the pseudo-terminal library's spawn entry points were entirely omitted from these security controls. An attacker capable of triggering a tool call can reach these unprotected entry points to spawn a shell, effectively bypassing the read-only constraints and executing arbitrary commands with the privileges of the server process. This flaw represents a significant risk for any application providing user-controlled Ruby execution environments. The vulnerability is addressed in version 1.6.1, which limits allowed requires to a data-only list and blocks dynamic dispatch to execution methods, while version 2.0.0 removes the tool entirely.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full command execution on the host server. This bypasses the intended read-only sandbox restrictions, potentially leading to unauthorized data access, persistence, or lateral movement within the environment where the server process resides.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the execute_ruby tool to version 1.6.1 or later immediately.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, remove the execute_ruby tool entirely (version 2.0.0 removal).\u003c/li\u003e\n\u003cli\u003eReview application logs for unauthorized execution of PTY-related Ruby modules that fall outside the intended business logic scope.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T19:10:25Z","date_published":"2026-08-27T19:10:25Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ruby-sandbox-bypass/","summary":"The execute_ruby tool fails to sanitize the pseudo-terminal library, allowing attackers to escape the Ruby sandbox and execute arbitrary system commands via spawn entry points.","title":"Sandbox Escape in execute_ruby Tool","url":"https://feed.craftedsignal.io/briefs/2026-08-ruby-sandbox-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Execute_ruby (1.4.0 to 1.6.0)","version":"https://jsonfeed.org/version/1.1"}