Lsegal Yard vulnerabilities
3 known vulnerabilities affecting lsegal/yard.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-41493P3HIGHCVSS 7.5fixed in 0.9.422026-05-08
CVE-2026-41493 [HIGH] CWE-22 CVE-2026-41493: YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was disco
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
nvd
CVE-2026-49342P4MEDIUMCVSS 5.3fixed in 0.9.442026-06-19
CVE-2026-49342 [MEDIUM] CWE-22 CVE-2026-49342: YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44,
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling
nvd
CVE-2024-27285P4MEDIUMCVSS 6.1fixed in 0.9.362024-02-28
CVE-2024-27285 [MEDIUM] CWE-79 CVE-2024-27285: YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentat
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
nvd