Path traversal in YARD - CVE-2026-41493
Published: April 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in yard server when handling unsanitized HTTP requests. A remote attacker can send a specially crafted request to disclose sensitive information.
Only deployments using yard server to serve documentation in untrusted environments without WEBrick and relying on --docroot are vulnerable.
Affected software
Ubuntu
openEuler
yard (Ubuntu package)
rubygem-yard
rubygem-yard-doc
How to mitigate CVE-2026-41493
yard (Ubuntu package) - addressed in versions 0.8.7.6+git20160220-3ubuntu0.1~esm2, 0.9.12-2ubuntu0.1~esm2, 0.9.24-1+deb11u1ubuntu0.1~esm1, 0.9.26-1ubuntu0.1+esm1, 0.9.36-1ubuntu0.1~esm1, 0.9.38-1ubuntu0.1~esm1
rubygem-yard - addressed in versions 0.9.26-4, 0.9.34-3
rubygem-yard-doc - addressed in versions 0.9.26-4, 0.9.34-3