CVE-2026-13601: Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications

Published Jun 29, 2026
·
Updated

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.

Other sources

A local sandbox escape and host information disclosure flaw was found in Yelp. A regression introduced in the companion yelp-xsl stylesheet component targets the gnome-42 and master development branches, leaving the application's Content Security Policy (CSP) style handling directives overly permissive.

A malicious or compromised sandboxed Flatpak application can programmatically abuse the standard host org.freedesktop.portal.OpenURI portal interface to pass crafted help layout files (ghelp:// or mallard extensions). Because the system portal processes this request silently without requiring user interaction, host-level Yelp is automatically invoked to parse the file outside the application container. The attacker-controlled layout leverages local XML inclusions to load arbitrary host-level files into memory, which are subsequently exfiltrated out-of-band to a remote server using a background CSS url() query embedded inside a structured SVG document.

Red Hat

Affected Software

7 affected components
Yelp
yelp-xsl
redhat Enterprise Linux=6.0
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
Gnome Yelp<49.1

Event History

Jun 29, 2026
Data Sourced
via Red Hat·08:53 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-13601?

The severity of CVE-2026-13601 is rated as high with a score of 7.1.

2

How does CVE-2026-13601 impact system security?

CVE-2026-13601 allows a malicious Flatpak application to disclose host files by exploiting an overly permissive Content Security Policy in Yelp.

3

What software is affected by CVE-2026-13601?

The vulnerability affects the Yelp software and its yelp-xsl component.

4

How can I mitigate CVE-2026-13601?

Mitigation for CVE-2026-13601 involves updating Yelp to a version that addresses the overly permissive Content Security Policy issue.

5

What is the cause of CVE-2026-13601?

CVE-2026-13601 is caused by Yelp's implementation of an overly permissive Content Security Policy which allows untrusted CSS stylesheets in SVG documents.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203