Logo
vulnerabilityCVE-2026-13601
Name
CVE-2026-13601
Source
NVD ( link)Debian ( link)
Description
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
yelp
Exploitable

Vulnerability Ratings#


7.1
CVSSv31
6.5
CVSSv31
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
yocto
master
42.2
Exploitable
yocto
scarthgap
42.2
Exploitable