CVE-2026-41493: yard: Possible arbitrary path traversal and file access via yard server
(updated )
A path traversal vulnerability was discovered in YARD <= 0.9.41 when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions.
The original patch in GHSA-xfhh-rx56-rxcr was incorrectly applied.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41493 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →