A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade yelp-libsUpgrade yelpUpgrade yelp-devel | Aug 6, 2026 | Jul 28, 2026 |
| Amazon Linux Ami 2 | — | Upgrade yelp-develUpgrade yelp-libsUpgrade yelp-debuginfoUpgrade yelp | Jul 22, 2026 | Jul 22, 2026 |
| Debian | — | Upgrade yelp | Jun 30, 2026 | Jun 30, 2026 |
| Redhat_linux | — | Upgrade yelp-develUpgrade yelp-debuginfoUpgrade yelpUpgrade yelp-libs-debuginfoNo solution existsUpgrade yelp-debugsourceUpgrade yelp-libs | Jul 17, 2026 | May 7, 2026 |
| Rocky_linux | — | Upgrade yelp-debuginfoUpgrade yelp-develUpgrade yelp-libs-debuginfoUpgrade yelpUpgrade yelp-libsUpgrade yelp-debugsource | Aug 5, 2026 | Aug 3, 2026 |
| Ubuntu | — | Upgrade libyelp0Upgrade yelp (Ubuntu Pro)Upgrade libyelp0 (Ubuntu Pro)Upgrade libyelp-1-0Upgrade yelp | Aug 12, 2026 | Aug 11, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub