PT-2026-37120 · Yard+2 · Yard+2
Segal
·
Published
2026-04-17
·
Updated
2026-06-05
·
CVE-2026-41493
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
YARD versions prior to 0.9.42
Description
A path traversal issue exists when using yard server to serve documentation. This flaw allows unsanitized HTTP requests to access arbitrary files on the host machine under certain conditions. Path traversal is a security gap where an attacker can access files and directories stored outside the intended folder by manipulating file paths.
Recommendations
Upgrade to version 0.9.42.
Perform path sanitization of HTTP requests at the webserver level.
Use WEBrick via
yard server -s webrick to perform default sanitization.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linuxmint
Ubuntu
Yard