Logo
vulnerabilityCVE-2025-3155
Name
CVE-2025-3155
Source
NVD ( link)Debian ( link)
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
yelp
Patched

Vulnerability Ratings#


7.4
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
42.2
Not Affected
yocto
scarthgap
42.2
Not Affected

Resolved with patches#


yelp (yocto:kirkstone)

#
Title
Author
Resolve
1
Initial fix for CVE-2025-3155 from parrot409
Shaun McCance <shaunm@gnome.org>
CVE-2025-3155