Junglewise Threat Intelligence

CVE-2026-41493: lsegal YARD path traversal in yard server

CVE-2026-41493 · Severity: high · CVSS 7.5 · Published 2026-05-08

Technologies: yard (RubyGems). Vendors: RubyGems.

Executive brief

YARD is a popular Ruby documentation tool used to generate and serve documentation for software projects. A security flaw in its built-in server component allows an attacker to bypass directory restrictions and access sensitive files on the host machine. This could lead to the exposure of private source code, configuration files, or other system data.

Technical details

A path traversal vulnerability (CWE-22) exists in the YARD documentation server when the `--docroot` option is utilized. The vulnerability stems from an incorrectly applied patch for a previous security issue (GHSA-xfhh-rx56-rxcr), which fails to properly sanitize HTTP request paths. A remote, unauthenticated attacker can send specially crafted HTTP requests to escape the intended documentation directory and read arbitrary files on the host system. This vulnerability specifically affects environments where YARD is used as a standalone server without a protective middleware like WEBrick, which typically handles path sanitization. The issue is resolved in version 0.9.42.

Affected products

  • lsegal yard <= 0.9.41

Timeline

  • 2026-04-16: patched: Version 0.9.42 released
  • 2026-04-17: advisory: GitHub Advisory GHSA-3jfp-46x4-xgfj published

References

Related threats