yard
YARD is a documentation generation tool for the Ruby programming language. It enables the user to generate consistent, usable documentation that can be exported to a number of formats very easily, and also supports extending for custom Ruby constructs such as custom class level definitions.
Activity
- Latest release
- 2mo ago
- Total releases
- 100
- Cadence
- ~14 days
- Last 12 months
- 8
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Mar 01, 2007
| Version | Released | |
|---|---|---|
0.9.45
patch
| ||
0.9.44
patch
| ||
0.9.43
patch
1 CVE
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev | ||
0.9.42
patch
1 CVE
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev | ||
0.9.41
patch
2 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev | ||
0.9.40
patch
2 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev | ||
0.9.39
patch
2 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev | ||
0.9.38
patch
2 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev | ||
0.9.37
patch
2 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev | ||
0.9.36
patch
2 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev | ||
0.9.35
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.34
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.33
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.30
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.31
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.32
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.29
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.28
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.27
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.26
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.25
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.24
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.23
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.21
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.22
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.20
patch
3 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
0.9.19
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.17
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.18
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.16
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.15
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.14
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.13
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.12
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.11
patch
4 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.10
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.9
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.8
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.7
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.6
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.5
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.4
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.3
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.2
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.1
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.9.0
minor
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.8.7.6
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.8.7.5
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.8.7.4
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
| ||
0.8.7.3
patch
5 CVEs
CVE-2026-49342
GHSA-pxcc-8665-phx8
Jun 26, 2026
YARD static cache reads raw traversal paths before router sanitization
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
SummaryYARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as The potential security risk seems low, as only html-ending files can be read, but still the risk of reading arbitrary html files is a confiendtiality issue in itself, which is why we decided to report. Please let us know if this is out of your project's scope. DetailsThe PoC
expected output:
The ImpactA remote unauthenticated HTTP client who can reach a YARD documentation server with Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 86 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.42
0.9.43
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.44
References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2026-41493
GHSA-3jfp-46x4-xgfj
Apr 17, 2026
yard: Possible arbitrary path traversal and file access via yard server
Medium
Network
Low
None
None
ImpactA path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied. PatchesPlease upgrade to YARD v0.9.42 immediately if you are relying on yard server to host documentation in any untrusted environments without WEBrick and rely on WorkaroundsFor users who cannot upgrade, it is possible to perform path sanitization of HTTP requests at your webserver level. WEBrick, for example, can perform such sanitization by default (which you can use via yard server -s webrick), as can certain rules in your webserver configuration. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 84 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.36
0.9.37
0.9.38
0.9.39
0.9.4
0.9.40
0.9.41
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.42
References Updated Jun 09, 2026 · Source: OSV.dev
CVE-2024-27285
GHSA-8mq4-9jjh-9xrc
Feb 28, 2024
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
5.4
/ 10
Medium
Network
Low
None
Required
Unchanged
Low
Low
None
SummaryThe "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. DetailsThe vulnerability stems from mishandling user-controlled data retrieved from the URL hash in the embedded JavaScript code within the "frames.erb" template file. Specifically, the script lacks proper sanitization of the hash data before utilizing it to establish the top-level window's location. This oversight permits an attacker to inject malicious JavaScript payloads through carefully crafted URLs. Snippet from "frames.erb": (v0.9.34)
(v0.9.35)
PoC (Proof of Concept)To exploit this vulnerability:
ImpactThis XSS vulnerability presents a substantial threat by enabling an attacker to execute arbitrary JavaScript code within the user's session context. Potential ramifications include session hijacking, theft of sensitive data, unauthorized access to user accounts, and defacement of websites. Any user visiting the compromised page is susceptible to exploitation. It is critical to promptly address this vulnerability to mitigate potential harm to users and preserve the application's integrity. Affected versions
0.2.0
0.2.1
0.2.2
0.2.3
0.2.3.2
0.2.3.3
0.2.3.4
0.2.3.5
0.4.0
0.5.0
0.5.1
0.5.1p1
+ 78 more Show less
0.5.2
0.5.3
0.5.4
0.5.5
0.5.6
0.5.7
0.5.8
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.6.7
0.6.8
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.8.0
0.8.1
0.8.2
0.8.2.1
0.8.3
0.8.4
0.8.4.1
0.8.5
0.8.5.1
0.8.5.2
0.8.6
0.8.6.1
0.8.6.2
0.8.7
0.8.7.1
0.8.7.2
0.8.7.3
0.8.7.4
0.8.7.5
0.8.7.6
0.9.0
0.9.1
0.9.10
0.9.11
0.9.12
0.9.13
0.9.14
0.9.15
0.9.16
0.9.17
0.9.18
0.9.19
0.9.2
0.9.20
0.9.21
0.9.22
0.9.23
0.9.24
0.9.25
0.9.26
0.9.27
0.9.28
0.9.29
0.9.3
0.9.30
0.9.31
0.9.32
0.9.33
0.9.34
0.9.35
0.9.4
0.9.5
0.9.6
0.9.7
0.9.8
0.9.9
Fixed in
0.9.36
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-1020001
GHSA-xfhh-rx56-rxcr
Jul 02, 2019
Path Traversal vulnerability that affects yard
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Possible arbitrary path traversal and file access via
|