Improper Neutralization of CRLF Sequences in Ymlr by Ufirstgroup
CVE-2026-65636
What is CVE-2026-65636?
The Ymlr product from Ufirstgroup is susceptible to an injection vulnerability that allows attackers to manipulate generated YAML documents via document comments. This occurs because the Ymlr.document!/2 method does not properly validate or escape line breaks in user-provided comment strings, resulting in the potential to forge keys, override values, or create additional document markers. Consequently, improperly parsed YAML could be processed as legitimate data by configuration loaders or CI pipelines. This flaw impacts multiple document encoding routines, making it critical for users to upgrade to versions 5.1.6 or later to mitigate the associated risks.
Affected Version(s)
ymlr 0.0.1 < 5.1.6
ymlr 0c11a86de83825e91c27cecaccb03f36416d8fe0 < 42a0bf8b2af44b0e7c42d0b7044c8588ca5866dc
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
