Vulnerabilities
Vulnerable Software
Yardoc:  >> Yard  >> 0.9.22  Security Vulnerabilities
YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allow unsanitized HTTP requests to access arbitrary files on the machine of a yard server host under certain conditions. This issue has been patched in version 0.9.42.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-05-08
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb" template file. This vulnerability is fixed in 0.9.36.
CVSS Score
5.4
EPSS Score
0.033
Published
2024-02-28


Contact Us

Shodan ® - All rights reserved