Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-pxcc-8665-phx8 | YARD static cache reads raw traversal paths before router sanitization |
Mon, 22 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Jun 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lsegal
Lsegal yard |
|
| Vendors & Products |
Lsegal
Lsegal yard |
Fri, 19 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue. | |
| Title | YARD static cache reads raw traversal paths before router sanitization | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-22T17:14:14.512Z
Reserved: 2026-05-29T14:35:45.903Z
Link: CVE-2026-49342
Updated: 2026-06-22T17:10:49.738Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-19T22:15:03Z
Github GHSA