Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 11

Количество 11

ubuntu логотип

CVE-2026-13601

около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
EPSS: Низкий
redhat логотип

CVE-2026-13601

3 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-13601

около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-13601

около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security ...

CVSS3: 7.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21295-1

21 день назад

Security update for yelp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3037-1

16 дней назад

Security update for yelp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3036-1

16 дней назад

Security update for yelp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3035-1

16 дней назад

Security update for yelp

EPSS: Низкий
github логотип

GHSA-f4vh-qr53-q5gv

около 1 месяца назад

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
EPSS: Низкий
oracle-oval логотип

ELSA-2026-47178

3 дня назад

ELSA-2026-47178: yelp security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-47177

4 дня назад

ELSA-2026-47177: yelp security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security ...

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21295-1

Security update for yelp

0%
Низкий
21 день назад
suse-cvrf логотип
SUSE-SU-2026:3037-1

Security update for yelp

0%
Низкий
16 дней назад
suse-cvrf логотип
SUSE-SU-2026:3036-1

Security update for yelp

0%
Низкий
16 дней назад
suse-cvrf логотип
SUSE-SU-2026:3035-1

Security update for yelp

0%
Низкий
16 дней назад
github логотип
GHSA-f4vh-qr53-q5gv

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад
oracle-oval логотип
ELSA-2026-47178

ELSA-2026-47178: yelp security update (IMPORTANT)

3 дня назад
oracle-oval логотип
ELSA-2026-47177

ELSA-2026-47177: yelp security update (IMPORTANT)

4 дня назад

Уязвимостей на страницу