CVE detail
CVE-2026-13601
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 18.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13601.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 29, 2026, 10:16 AM - https://gitlab.gnome.org/GNOME/yelp/-/work_items/238gitlab.gnome.org
No excerpt available.
Exploitgitlab.gnome.orgJun 29, 2026, 10:16 AM - https://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639gitlab.gnome.org
No excerpt available.
Exploitgitlab.gnome.orgJun 29, 2026, 10:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2494110bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 29, 2026, 10:16 AM No excerpt available.
Third Party Advisoryblogs.gnome.orgJun 29, 2026, 10:16 AM- https://access.redhat.com/security/cve/CVE-2026-13601access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 29, 2026, 10:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2023-5557CVSS 7.5 · High
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has…
- CVE-2023-3089CVSS 7.0 · High
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were F…
- CVE-2025-3155CVSS 7.4 · High
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents,…
- CVE-2026-18015CVSS 9.6 · Critical
Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chr…
- CVE-2026-17943CVSS 4.3 · Medium
Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium secur…
- CVE-2026-17936CVSS 6.5 · Medium
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigat…