Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the appropriate security update when they becomes available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Mon, 29 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Jun 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information. | |
| Title | Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-693 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-06-29T18:44:24.447Z
Reserved: 2026-06-29T08:05:06.046Z
Link: CVE-2026-13601
Updated: 2026-06-29T13:26:43.482Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T11:30:05Z