← Volver al buscador de CVEs

CVE-2026-49342

Descripción

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD-s static cache lookup reads a request path before the router-s path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue.

CVSS 5.3EPSS 0.40299999999999997%Riesgo 0.55
Ver fuente
Publicación
2026-06-19 20:16:18
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N