GHSA-42q4-rvcw-q7wcMediumCVSS 6.2

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler...

Published
September 9, 2026
Last Modified
September 9, 2026

🔗 CVE IDs covered (1)

📋 Description

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top level to crash the embedding application and cause denial of service.

🔗 References (5)