CVE-2026-41493

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
Configurations

Configuration 1 (hide)

cpe:2.3:a:yardoc:yard:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-08 14:16

Updated : 2026-06-17 10:46


NVD link : CVE-2026-41493

Mitre link : CVE-2026-41493

CVE.ORG link : CVE-2026-41493


JSON object : View

Products Affected

yardoc

  • yard
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')