CVE-2025-3155
published 2025-04-03CVE-2025-3155: A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to…
PriorityP351high7.4CVSS 3.1
AVNACLPRNUIRSCCHINAN
EPSS
12.39%
95.8th percentile
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | yelp | < yelp 42.2-1+deb12u1 (bookworm) | yelp 42.2-1+deb12u1 (bookworm) |
| debian | yelp-xsl | < yelp 42.2-1+deb12u1 (bookworm) | yelp 42.2-1+deb12u1 (bookworm) |
| gnome | yelp | — | — |
| gnome | yelp | >= 0 < 3.38.3-1+deb11u1 | 3.38.3-1+deb11u1 |
| gnome | yelp | >= 0 < 42.2-1+deb12u1 | 42.2-1+deb12u1 |
| gnome | yelp | >= 0 < 42.2-3 | 42.2-3 |
| gnome | yelp | >= 0 < 42.2-3 | 42.2-3 |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64 | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_arm64_eus | — | — |
| redhat | codeready_linux_builder_for_eus | — | — |
| redhat | codeready_linux_builder_for_eus | — | — |
| redhat | codeready_linux_builder_for_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
| redhat | codeready_linux_builder_for_ibm_z_systems_eus | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
osv7.4HIGH
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications
vendor_redhat·2026-05-07·CVSS 7.1
CVE-2026-13601 [HIGH] CWE-693 yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications
yelp: yelp-xsl: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Statement: This vulnerability affects the Content Security Policy (CSP) implementation handling help documents
Ubuntu
Yelp vulnerability
vendor_ubuntu·2025-04-23
CVE-2025-3155 Yelp vulnerability
Title: Yelp vulnerability
Summary: Yelp could be made to expose sensitive information over the network.
It was discovered that Yelp incorrectly handled paths in ghelp URLs. A
remote attacker could use this issue to trick users into opening malicious
downloaded help files and exfiltrate sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
yelp: Arbitrary file read
vendor_redhat·2025-04-03·CVSS 7.4
CVE-2025-3155 [HIGH] CWE-601 yelp: Arbitrary file read
yelp: Arbitrary file read
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Statement: Red Hat has evaluated this with a Important severity as this requires user interaction and possibly access to add malicious JavaScript content, allowing the attacker to exfiltrate files from the victim's end with minimal user interaction.
Mitigation: Currently, no mitigation is
Debian
CVE-2025-3155: yelp - A flaw was found in Yelp. The Gnome user help application allows the help docume...
vendor_debian·2025·CVSS 7.4
CVE-2025-3155 [HIGH] CVE-2025-3155: yelp - A flaw was found in Yelp. The Gnome user help application allows the help docume...
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Scope: local
bookworm: resolved (fixed in 42.2-1+deb12u1)
bullseye: resolved (fixed in 3.38.3-1+deb11u1)
forky: resolved (fixed in 42.2-3)
sid: resolved (fixed in 42.2-3)
trixie: resolved (fixed in 42.2-3)
GHSA
GHSA-h7mx-548v-cr9r: A flaw was found in Yelp
ghsa_unreviewed·2025-04-03
CVE-2025-3155 [MEDIUM] CWE-601 GHSA-h7mx-548v-cr9r: A flaw was found in Yelp
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
OSV
CVE-2025-3155: A flaw was found in Yelp
osv·2025-04-03·CVSS 7.4
CVE-2025-3155 [HIGH] CVE-2025-3155: A flaw was found in Yelp
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2025:4450https://access.redhat.com/errata/RHSA-2025:4451https://access.redhat.com/errata/RHSA-2025:4455https://access.redhat.com/errata/RHSA-2025:4456https://access.redhat.com/errata/RHSA-2025:4457https://access.redhat.com/errata/RHSA-2025:4505https://access.redhat.com/errata/RHSA-2025:4532https://access.redhat.com/errata/RHSA-2025:7430https://access.redhat.com/errata/RHSA-2025:7569https://access.redhat.com/security/cve/CVE-2025-3155https://bugzilla.redhat.com/show_bug.cgi?id=2357091https://gitlab.gnome.org/GNOME/yelp/-/issues/221http://www.openwall.com/lists/oss-security/2025/04/04/1https://lists.debian.org/debian-lts-announce/2025/05/msg00036.htmlhttps://lists.debian.org/debian-lts-announce/2025/05/msg00037.htmlhttps://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2
2025-04-03
Published