#1136076 yard: CVE-2026-41493

Package:
src:yard
Source:
src:yard
Submitter:
Salvatore Bonaccorso
Date:
2026-05-09 08:47:02 UTC
Severity:
normal
Tags:
#1136076#5
Date:
2026-05-09 08:45:46 UTC
From:
To:
Hi,

The following vulnerability was published for yard.

CVE-2026-41493[0]:
| YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path
| traversal vulnerability was discovered in YARD when using yard server
| to serve documentation. This bug would allow unsanitized HTTP requests
| to access arbitrary files on the machine of a yard server host under
| certain conditions. This issue has been patched in version 0.9.42.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-41493
https://www.cve.org/CVERecord?id=CVE-2026-41493
[1] https://github.com/lsegal/yard/security/advisories/GHSA-3jfp-46x4-xgfj

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore