Jekyllrb maintains Jekyll, a static site generator widely used for building documentation sites and blogs from markdown and templates. The vendor's vulnerability exposure centers on improper link resolution and file-access sequencing, a class of flaw that can arise when file operations lack adequate path canonicalization or symlink validation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jekyllrb over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17567HIGH Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file | Sep 28, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jekyllrb.
Media articles that mention a CVE ID that affects a product developed by Jekyllrb — matched by CVE ID, not by vendor name.