Description
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Published: 2026-06-29
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Yelp the Content Security Policy implemented by yelp‑xsl was found to be overly permissive. A malicious Flatpak application can use the OpenURI portal to open specially crafted help content. By embedding an untrusted CSS stylesheet inside a structured SVG document the attacker can trick Yelp into evaluating local XML inclusions. The result is that Yelp will download remote CSS resources that can reference local host files, allowing the attacker to read arbitrary files that are normally inaccessible to the application. This flaw can lead to the unauthorized disclosure of sensitive information present on the host system.

Affected Systems

Red Hat Enterprise Linux distributions from version 6 through 10 are affected because they include the Yelp application. The flaw is present in all current releases listed in the CNA data: RHEL 6, RHEL 7, RHEL 8, RHEL 9, and RHEL 10.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, and the lack of an EPSS value does not lessen the importance of the vulnerability. This issue is not yet tracked in the CISA KEV catalog, but the attack can occur in a local or remote context where a user can deploy a malicious Flatpak application. The attacker would need to supply the crafted SVG/CSS payload; once executed, Yelp’s improper CSP allows the sandbox to be bypassed and host files to be disclosed. Because the condition requires an attacker capable of running a Flatpak package, the exploitation probability is moderate to high in environments where Flatpak applications are trusted or unverified.

Generated by OpenCVE AI on June 29, 2026 at 11:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Yelp to the latest version containing the patch referenced by commit c8c8244c8a812860782d635890c9b6c43ecc2639.
  • Restart the Flatpak sandbox for Yelp to ensure the new policy is in effect.
  • Restrict Flatpak applications to only the minimum necessary permissions, particularly by tightening the OpenURI portal access for Yelp.

Generated by OpenCVE AI on June 29, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 29 Jun 2026 10:15:00 +0000

Type Values Removed Values Added
Description A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Title Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-693
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-06-29T10:03:06.274Z

Reserved: 2026-06-29T08:05:06.046Z

Link: CVE-2026-13601

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-29T11:30:05Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure