Excessive Content Security Policy Flaw in Yelp's XSL Implementation
CVE-2026-13601

7.1HIGH

What is CVE-2026-13601?

A significant vulnerability exists in Yelp due to an overly permissive Content Security Policy (CSP) within its yelp-xsl implementation. This flaw allows a malicious Flatpak application to exploit crafted help content via the OpenURI portal. By incorporating an untrusted CSS stylesheet into a structured SVG document, an attacker can bypass Flatpak's sandbox isolation. This may lead to the unauthorized evaluation of local XML inclusions, thereby disclosing sensitive user-readable host files through remote CSS resource requests.

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Codean Labs for reporting this issue.
.