Path traversal in YARD - CVE-2026-49342
Published: May 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in static cache lookup when handling request paths before router path cleanup. A remote attacker can send a specially crafted request containing parent-directory components to disclose sensitive information.
Only deployments with a configured document root are vulnerable, and only readable regular files reachable through the forced .html suffix can be returned.
Affected software
openEuler
rubygem-yard
rubygem-yard-doc
How to mitigate CVE-2026-49342
rubygem-yard - update to 0.9.34-4
rubygem-yard-doc - update to 0.9.34-4