Back

HIGH

Yelp: arbitrary file read

Published Apr 3, 2025

Description

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

Affected products

Remediation

Vendor solution

Currently, no mitigation is available for this vulnerability.

Red Hat statement

Red Hat has evaluated this with a Important severity as this requires user interaction and possibly access to add malicious JavaScript content, allowing the attacker to exfiltrate files from the victim's end with minimal user interaction.

Red Hat mitigation

Currently, no mitigation is available for this vulnerability.

Weaknesses (1)

References (19)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Apr 3, 2025
Updated Jun 29, 2026
Reserved Apr 3, 2025

CISA Vulnrichment

Updated Apr 8, 2025

NVD

Status Modified
Modified Jun 29, 2026

Red Hat

Severity Important
Public date Apr 3, 2025
Bugzilla 2357091

ENISA EUVD

Assigner redhat
Published Apr 3, 2025
Updated Jun 29, 2026

GitHub

No data