Excessive Content Security Policy Flaw in Yelp's XSL Implementation
CVE-2026-13601
7.1HIGH
What is CVE-2026-13601?
A significant vulnerability exists in Yelp due to an overly permissive Content Security Policy (CSP) within its yelp-xsl implementation. This flaw allows a malicious Flatpak application to exploit crafted help content via the OpenURI portal. By incorporating an untrusted CSS stylesheet into a structured SVG document, an attacker can bypass Flatpak's sandbox isolation. This may lead to the unauthorized evaluation of local XML inclusions, thereby disclosing sensitive user-readable host files through remote CSS resource requests.
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Codean Labs for reporting this issue.