Yelp: arbitrary file read
Published Apr 3, 2025
7.4
HIGHCVSS 3.1
EPSS 14.21%
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Affected products
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 7 | affected | |
| Red Hat | Red Hat Enterprise Linux 9 | affected |
Configuration 2
- 11.0
Configuration 3
- 8.0
- 9.0
- 8.0_aarch64
- 9.0_aarch64
- 8.8_aarch64
- 9.2_aarch64
- 9.4_aarch64
- 9.6_aarch64
- 8.8
- 9.2
- 9.4
- 8.0_s390x
- 9.0_s390x
- 8.8_s390x
- 9.2_s390x
- 9.4_s390x
- 9.6_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 8.8_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 9.6_ppc64le
- 8.0
- 9.0
- 9.2
- 9.4
- 9.6
- 8.0
- 8.8_aarch64
- 9.0_aarch64
- 9.2_aarch64
- 9.4_aarch64
- 9.6_aarch64
- 8.0_s390x
- 9.0_s390x
- 8.8_s390x
- 9.2_s390x
- 9.4_s390x
- 9.6_s390x
- 8.0_ppc64le
- 9.0_ppc64le
- 8.8_ppc64le
- 9.2_ppc64le
- 9.4_ppc64le
- 9.6_ppc64le
- 8.2
- 8.4
- 8.6
- 9.2
- 9.4
- 9.6
- 8.4
- 8.6
- 8.8
- 8.4
- 8.6
- 8.8
- 9.0
- 9.2
- 9.4
No data.
Red Hat Enterprise Linux 8
yelp-2:3.28.1-3.el8_10.1
Fixed · RHSA-2025:7569
Red Hat Enterprise Linux 8
yelp-xsl-0:3.28.0-2.el8_10.1
Fixed · RHSA-2025:7569
Red Hat Enterprise Linux 8.2 Advanced Update Support
yelp-2:3.28.1-3.el8_2.1
Fixed · RHSA-2025:4457
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
yelp-2:3.28.1-3.el8_4.1
Fixed · RHSA-2025:4451
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
yelp-2:3.28.1-3.el8_4.1
Fixed · RHSA-2025:4451
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
yelp-2:3.28.1-3.el8_4.1
Fixed · RHSA-2025:4451
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
yelp-2:3.28.1-3.el8_6.1
Fixed · RHSA-2025:4455
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
yelp-2:3.28.1-3.el8_6.1
Fixed · RHSA-2025:4455
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
yelp-2:3.28.1-3.el8_6.1
Fixed · RHSA-2025:4455
Red Hat Enterprise Linux 8.8 Extended Update Support
yelp-2:3.28.1-3.el8_8.1
Fixed · RHSA-2025:4532
Red Hat Enterprise Linux 9
yelp-2:40.3-2.el9_6.1
Fixed · RHSA-2025:7430
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
yelp-2:40.3-2.el9_0.1
Fixed · RHSA-2025:4450
Red Hat Enterprise Linux 9.2 Extended Update Support
yelp-2:40.3-2.el9_2.1
Fixed · RHSA-2025:4505
Red Hat Enterprise Linux 9.4 Extended Update Support
yelp-2:40.3-2.el9_4.1
Fixed · RHSA-2025:4456
Red Hat Enterprise Linux 6
yelp
Out of support scope
Red Hat Enterprise Linux 7
yelp
Affected
Red Hat Enterprise Linux 7
yelp-xsl
Affected
Red Hat Enterprise Linux 9
yelp-xsl
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | yelp-2:3.28.1-3.el8_10.1 | Fixed | RHSA-2025:7569 |
| Red Hat Enterprise Linux 8 | yelp-xsl-0:3.28.0-2.el8_10.1 | Fixed | RHSA-2025:7569 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | yelp-2:3.28.1-3.el8_2.1 | Fixed | RHSA-2025:4457 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | yelp-2:3.28.1-3.el8_4.1 | Fixed | RHSA-2025:4451 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | yelp-2:3.28.1-3.el8_4.1 | Fixed | RHSA-2025:4451 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | yelp-2:3.28.1-3.el8_4.1 | Fixed | RHSA-2025:4451 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | yelp-2:3.28.1-3.el8_6.1 | Fixed | RHSA-2025:4455 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | yelp-2:3.28.1-3.el8_6.1 | Fixed | RHSA-2025:4455 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | yelp-2:3.28.1-3.el8_6.1 | Fixed | RHSA-2025:4455 |
| Red Hat Enterprise Linux 8.8 Extended Update Support | yelp-2:3.28.1-3.el8_8.1 | Fixed | RHSA-2025:4532 |
| Red Hat Enterprise Linux 9 | yelp-2:40.3-2.el9_6.1 | Fixed | RHSA-2025:7430 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | yelp-2:40.3-2.el9_0.1 | Fixed | RHSA-2025:4450 |
| Red Hat Enterprise Linux 9.2 Extended Update Support | yelp-2:40.3-2.el9_2.1 | Fixed | RHSA-2025:4505 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | yelp-2:40.3-2.el9_4.1 | Fixed | RHSA-2025:4456 |
| Red Hat Enterprise Linux 6 | yelp | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | yelp | Affected | n/a |
| Red Hat Enterprise Linux 7 | yelp-xsl | Affected | n/a |
| Red Hat Enterprise Linux 9 | yelp-xsl | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Currently, no mitigation is available for this vulnerability.
Red Hat statement
Red Hat has evaluated this with a Important severity as this requires user interaction and possibly access to add malicious JavaScript content, allowing the attacker to exfiltrate files from the victim's end with minimal user interaction.
Red Hat mitigation
Currently, no mitigation is available for this vulnerability.
References (19)
- http://www.openwall.com/lists/oss-security/2025/04/04/1 Mailing List
- https://access.redhat.com/errata/RHSA-2025:4450 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4451 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4455 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4456 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4457 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4505 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4532 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7430 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7569 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-3155 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2357091 issue-trackingx_refsource_REDHATExploitIssue TrackingThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-9635 Advisory
- https://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2 exploitThird Party Advisory
- https://gitlab.gnome.org/GNOME/yelp/-/issues/221
- https://lists.debian.org/debian-lts-announce/2025/05/msg00036.html Mailing List
- https://lists.debian.org/debian-lts-announce/2025/05/msg00037.html Mailing List
- https://nvd.nist.gov/vuln/detail/CVE-2025-3155
- https://www.cve.org/CVERecord?id=CVE-2025-3155
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data