CVE-2026-13601

🟡 Monitoruj

Nadmiernie luźna polityka CSP w Yelp umożliwia ujawnienie wrażliwych informacji.

CVSS
7.1
EPSS
0.0%
Exploit
none
Vendor
Opis źródłowy (NVD)

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.1
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.0%
Opublikowano (NVD)2026-06-29 10:16:30 UTC
Ostatnia modyfikacja (NVD)2026-06-29 18:51:46 UTC
Referencje