Yardoc's vulnerability footprint concentrates in a single documentation-generation tool (Yard) with a focused set of disclosures centered on web-facing input handling, including path-traversal and cross-site scripting weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yardoc over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41493HIGH YARD is a Ruby Documentation tool. Prior to version 0.9.42, a path traversal vulnerability was discovered in YARD when using yard server to serve documentation. This bug would allo | May 8, 2026 | 7.5 | 27 | NO | NO |
CVE-2017-17042HIGH lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal atta | Nov 28, 2017 | 7.5 | 25 | NO | NO |
CVE-2019-1020001HIGH yard before 0.9.20 allows path traversal. | Jul 29, 2019 | 7.5 | 23 | NO | NO |
CVE-2024-27285MEDIUM YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate saniti | Feb 28, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yardoc.
Media articles that mention a CVE ID that affects a product developed by Yardoc — matched by CVE ID, not by vendor name.