VendorsYardocyardall versions
Vulnerabilities

Yardoc Yard

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2017-17042
lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.
Published 2017-11-28 · Modified
7.5EPSS 0.029
CVE-2019-1020001
yard before 0.9.20 allows path traversal.
Published 2019-07-29 · Modified
7.5EPSS 0.023
CVE-2026-41493
yard: Possible arbitrary path traversal and file access via yard server
Published 2026-05-08 · Analyzed
7.5EPSS 0.005
CVE-2024-27285
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
Published 2024-02-28 · Analyzed
6.1EPSS 0.011