Vulnerabilities
Vulnerable Software
Gnome:  >> Yelp  >> 2.27.3  Security Vulnerabilities
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
CVSS Score
7.1
EPSS Score
0.001
Published
2026-06-29


Contact Us

Shodan ® - All rights reserved