Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-13601

Опубликовано: 29 июн. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.1

Описание

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

РелизСтатусПримечание
devel

not-affected

49.1-1
esm-infra-legacy/xenial

released

3.18.1-1ubuntu4+esm1
esm-infra/bionic

released

3.26.0-1ubuntu2+esm1
esm-infra/focal

released

3.36.2-0ubuntu1.1+esm1
jammy

released

42.1-1ubuntu0.2
noble

released

42.2-1ubuntu0.24.04.2
questing

ignored

end of life, was needed
resolute

released

49.0-5ubuntu0.1
upstream

released

49.1-1

Показывать по

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
redhat
5 месяцев назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
nvd
3 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
debian
3 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security ...

suse-cvrf
3 месяца назад

Security update for yelp

suse-cvrf
2 месяца назад

Security update for yelp

7.1 High

CVSS3