HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-41493 — YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vul...

·Source: NIST NVD

Updated:

Executive Summary

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.

Analysis

YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42. CVSS Score: 7.5. Published: 2026-05-08T14:16:33.550.

Indicators of Compromise (1)

CVE (1)
CVE-2026-41493
Source Attribution

Originally published by NIST NVD on May 8, 2026. Verified by: NIST.

Related Threats