CVE-2018-10199 is a critical use-after-free vulnerability (CWE-416) affecting mruby versions up to and including 1.4.0, specifically in the src/io.c::File#initialize_copy() function. This vulnerability allows an attacker to execute arbitrary code if they can induce the execution of Ruby code. With a CVSS score of 9.8 (CRITICAL), it presents a high risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4.0CPE matchmatch criteria | cpe:2.3:a:mruby:mruby:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.