Bug 2494117 - CVE-2026-13601 yelp: Overly Permissive Content Security Policy in Yelp Allows Host File Disclosure from Flatpak Applications [fedora-all]
Summary: CVE-2026-13601 yelp: Overly Permissive Content Security Policy in Yelp Allows...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: yelp
Version: 45
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: David King
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["fa2bfef5-2e52-4d56-8e81-a...
: 2494116 (view as bug list)
Depends On:
Blocks: CVE-2026-13601
TreeView+ depends on / blocked
 
Reported: 2026-06-29 09:14 UTC by TEJ RATHI
Modified: 2026-08-26 20:38 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-08-26 20:38:47 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
GNOME Gitlab GNOME/yelp/-/work_items/238 0 None None None 2026-08-26 01:03:39 UTC

Description TEJ RATHI 2026-06-29 09:14:17 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A local sandbox escape and host information disclosure flaw was found in Yelp. A regression introduced in the companion yelp-xsl stylesheet component targets the gnome-42 and master development branches, leaving the application's Content Security Policy (CSP) style handling directives overly permissive.

A malicious or compromised sandboxed Flatpak application can programmatically abuse the standard host org.freedesktop.portal.OpenURI portal interface to pass crafted help layout files (ghelp:// or mallard extensions). Because the system portal processes this request silently without requiring user interaction, host-level Yelp is automatically invoked to parse the file outside the application container. The attacker-controlled layout leverages local XML inclusions to load arbitrary host-level files into memory, which are subsequently exfiltrated out-of-band to a remote server using a background CSS url() query embedded inside a structured SVG document.

Comment 1 Aoife Moloney 2026-08-17 15:01:32 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.

Comment 2 Adrian Vovk 2026-08-26 01:10:43 UTC
*** Bug 2494116 has been marked as a duplicate of this bug. ***

Comment 3 Adrian Vovk 2026-08-26 20:38:47 UTC
The fix was rolled out in yelp 49.2, which is the current version in f43 through rawhide. Thus, we can close this as fixed.


Note You need to log in before you can comment on or make changes to this bug.