Yardoc
Yardoc Yard: vulnerabilities and CVEs
Yardoc Yard has 5 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months2
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49342 | Medium (5.3) | 0.40% | — | Jun 19, 2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with… |
| CVE-2026-41493 | Medium (6.9) | 0.52% | — | May 8, 2026 | YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access… |
| CVE-2024-27285 | Medium (6.1) | 1.1% | — | Feb 28, 2024 | YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the… |
| CVE-2019-1020001 | High (7.5) | 2.3% | — | Jul 29, 2019 | yard before 0.9.20 allows path traversal. |
| CVE-2017-17042 | High (7.5) | 2.9% | — | Nov 28, 2017 | lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files. |