Medium severity5.3NVD Advisory· Published Jun 19, 2026· Updated Jun 23, 2026
CVE-2026-49342
CVE-2026-49342
Description
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as /../yard-cache-secret.html is joined against that root and can return a readable sibling .html file outside the intended static tree. Version 0.9.44 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yardRubyGems | < 0.9.44 | 0.9.44 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.