PT-2026-37120 · Yard+2 · Yard+2

Segal

·

Published

2026-04-17

·

Updated

2026-06-05

·

CVE-2026-41493

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions YARD versions prior to 0.9.42
Description A path traversal issue exists when using yard server to serve documentation. This flaw allows unsanitized HTTP requests to access arbitrary files on the host machine under certain conditions. Path traversal is a security gap where an attacker can access files and directories stored outside the intended folder by manipulating file paths.
Recommendations Upgrade to version 0.9.42. Perform path sanitization of HTTP requests at the webserver level. Use WEBrick via yard server -s webrick to perform default sanitization.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41493
GHSA-3JFP-46X4-XGFJ
OESA-2026-2205
OESA-2026-2206
OESA-2026-2207
OESA-2026-2208
OESA-2026-2285
USN-8394-1

Affected Products

Linuxmint
Ubuntu
Yard