Executive brief
YARD is a documentation generation tool for Ruby that includes a local server for viewing documentation. A security flaw in its static file caching mechanism allows an attacker to view HTML files on the server that are outside of the intended documentation folder. This could lead to the exposure of sensitive information if other HTML files are stored on the same system.
Technical details
A path traversal vulnerability exists in YARD's `check_static_cache` method within the `Router` class. When the `--docroot` option is enabled, the server joins the user-provided request path with the document root using `File.join` before performing path sanitization. An unauthenticated remote attacker can use `..` sequences to escape the document root and read any file ending in `.html` that the server process has permission to access. This occurs because the static cache check returns a response before the `final_options` sanitization logic is executed. The issue is fixed in version 0.9.44.
Affected products
- lsegal yard < 0.9.44
Timeline
- 2026-05-25: disclosed
- 2026-06-19: advisory: NVD publication date
- 2026-06-26: patched: GitHub Advisory reviewed and updated