PT-2026-51019 · Yard · Yard

·

CVE-2026-49342

·

Published

2026-06-19

·

Updated

2026-07-06

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions YARD versions prior to 0.9.44
Description YARD is a documentation generation tool for the Ruby programming language. The static cache lookup reads a request path before the router's path cleanup process occurs. When a server is configured with a document root, a traversal path such as '/../yard-cache-secret.html' can be joined against that root, allowing the return of a readable sibling .html file located outside the intended static tree.
Recommendations Update to version 0.9.44.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49342
GHSA-PXCC-8665-PHX8
OESA-2026-2851
OESA-2026-2852

Affected Products

Yard