CVE-2026-49342: YARD Path Traversal Vulnerability in Ruby Documentation Tool
YARD, a popular documentation generator for Ruby, contains a path traversal vulnerability that allows attackers to read HTML files outside the intended documentation directory. The flaw occurs because the application checks its static file cache before properly cleaning up request paths, enabling specially crafted URLs to escape the configured document root and access sibling files. This affects versions prior to 0.9.44 and is fixed in that release.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-22
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-19 / 2026-06-23
NVD description (verbatim)
YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
YARD's static cache lookup mechanism processes incoming requests before the router normalizes path components. An attacker can craft a request containing path traversal sequences (e.g., `/../yard-cache-secret.html`) that, when joined against the configured document root, resolves to HTML files in parent or sibling directories. The vulnerability stems from the order of operations: cache lookup happens first, allowing the traversal payload to be resolved before path cleanup strips dangerous sequences. This is a classic path normalization bypass (CWE-22) where insufficient input validation during early processing stages allows directory escape.
Business impact
Organizations using YARD to serve auto-generated API documentation may expose sensitive `.html` files containing configuration details, build artifacts, or information about the application structure. Since YARD is commonly deployed in development and CI/CD environments where documentation servers may be publicly accessible, the leak of adjacent files could aid reconnaissance attacks or expose internal documentation not intended for public consumption. The vulnerability does not allow arbitrary file write or system compromise, limiting the scope to information disclosure.
Affected systems
YARD versions prior to 0.9.44 are vulnerable. The issue manifests when YARD is configured with a document root and serves static HTML files. Ruby projects using YARD for documentation generation—particularly those exposing the generated docs via an HTTP server—are at risk. The attack requires network access to the YARD instance and does not depend on authentication or user interaction.
Exploitability
Exploitation is straightforward and requires only network connectivity. An attacker can test for the vulnerability by requesting paths like `/../filename.html` against the YARD server and observing whether files outside the documentation tree are returned. The attack is reliable in default configurations and does not require authentication, special privileges, or user interaction. However, successful exploitation is limited to discovering and reading existing HTML files; an attacker cannot create, modify, or delete files or achieve code execution.
Remediation
Upgrade YARD to version 0.9.44 or later. This patch version corrects the order of operations so that path normalization occurs before cache lookup, preventing traversal sequences from resolving to out-of-scope files. No configuration changes or workarounds are needed; patching is the sole remediation. Projects should audit which versions are in use across their Ruby documentation tooling.
Patch guidance
Apply the update to YARD 0.9.44 or newer. If YARD is vendored or pinned in your Gemfile, update the version constraint (e.g., `gem 'yard', '~> 0.9.44'`) and run `bundle update yard`. For systems managing Ruby tools via package managers, verify that the package repository offers version 0.9.44 or later. After patching, restart any documentation servers to ensure the new code is loaded. No database migrations or additional setup steps are required.
Detection guidance
Monitor access logs for request patterns containing `/../` or similar path traversal sequences targeting `.html` files. Search for 404s or 200 responses to unusual paths like `/../yard-cache-secret.html` or similar. Review network traffic to YARD instances for encoded traversal attempts. Additionally, audit your YARD deployment configuration to confirm you are running version 0.9.44 or later by checking the Gemfile.lock or running `yard -v`. If documentation is served publicly, consider restricting access by IP or requiring authentication at the web server level as a defense-in-depth measure.
Why prioritize this
This vulnerability merits prompt patching because it affects a widely-used tool, requires no authentication or user interaction, and the fix is simple and low-risk. While the impact is limited to information disclosure, YARD is often deployed in development and build environments where exposure of adjacent files could leak sensitive internal documentation or configuration. The CVSS score of 5.3 (Medium) reflects the ease of exploitation balanced against the lack of code execution or system compromise. Organizations should prioritize this within a normal maintenance cycle but do not need to treat it as an emergency.
Risk score, explained
CVSS 3.1 score of 5.3 (Medium) reflects: network-accessible attack surface (AV:N), low attack complexity with no special conditions required (AC:L), no authentication needed (PR:N), no user interaction (UI:N), and impact limited to confidentiality of files within the server's filesystem scope (C:L). Integrity and availability are not affected, so I and A are set to N. The scope is unchanged (S:U). The score appropriately captures a real but non-critical information disclosure risk in a documentation tool.
Frequently asked questions
Can this vulnerability lead to remote code execution?
No. The vulnerability is limited to reading existing HTML files. An attacker cannot write, modify, or execute code through this path traversal. If sensitive executable files are stored in the YARD document tree, an attacker could read them, but would need a separate code execution vulnerability to run them.
Do I need to update if YARD is only used in development and not exposed to the internet?
If your YARD instance is only accessible from trusted internal networks, the risk is lower. However, updating to 0.9.44 is still recommended because internal personnel or compromised development machines could exploit it, and patching requires minimal effort. Verify your deployment architecture before deciding to defer.
Will updating YARD break my existing documentation or configuration?
Version 0.9.44 is a patch release focused on security; it should not introduce breaking changes to your documentation generation or existing configuration. However, test the update in a staging environment first if your documentation build is part of a critical pipeline.
How do I know if someone has exploited this vulnerability on my system?
Check your web server access logs for unusual requests containing `/../` or other path traversal patterns. Look for 200 responses to files outside your intended documentation directory, or 404 errors for paths that seem suspicious. If YARD runs behind a reverse proxy, check both the YARD and proxy logs. Correlate timestamps with known network access patterns to your infrastructure.
This analysis is based on the CVE description and publicly available information current as of the advisory publication date. Readers should consult the official YARD project repository and Ruby security advisories for the most current patch status and vendor guidance. This vulnerability assessment does not constitute legal advice or liability determination. Organizations should validate patch applicability against their specific deployment and test updates in non-production environments before broad deployment. No exploit code or weaponized proof-of-concept is provided; security researchers should follow responsible disclosure practices. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2018-25393MEDIUMNavigate CMS 2.8.5 Path Traversal Vulnerability (CVSS 6.5)
- CVE-2018-25421MEDIUMOpen STA Manager 2.3 Path Traversal File Download Vulnerability
- CVE-2019-25734MEDIUMContact Form by WD CSRF & Local File Inclusion Vulnerability
- CVE-2019-25740MEDIUMJoomla com_jsjobs Arbitrary File Deletion Vulnerability
- CVE-2022-50953MEDIUMWordPress admin-word-count-column Plugin Local File Read Vulnerability
- CVE-2024-47263MEDIUMSynology Hyper Backup Path Traversal – Admin Privilege Required
- CVE-2024-47273MEDIUMSynology Hyper Backup Path Traversal Vulnerability (4.3 MEDIUM)
- CVE-2025-24268MEDIUMmacOS Path Traversal Vulnerability – Patch Sequoia 15.4