HIGHVulnerability
Verified
Global
NVD HIGH: CVE-2026-41493 — YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vul...
·Source: NIST NVD
Updated:
Executive Summary
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
Analysis
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42. CVSS Score: 7.5. Published: 2026-05-08T14:16:33.550.