Current section
1 Advisory
Jump to
Current section
1 Advisory
YAML injection via unescaped newlines in ymlr document comments
Affected Versions
>= 0.0.1 and < 5.1.6
References
- https://cna.erlef.org/cves/CVE-2026-65636.html
- https://github.com/ufirstgroup/ymlr/commit/42a0bf8b2af44b0e7c42d0b7044c8588ca5866dc
- https://github.com/ufirstgroup/ymlr/commit/7e53061fb2809b787fba0373c46b78e253c83adc
- https://github.com/ufirstgroup/ymlr/security/advisories/GHSA-p8qx-7cp9-v6c9
- https://hex.pm/packages/ymlr