Security Advisory

CVE-2026-13601

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-29 09:20:40
Last updated 2026-07-15 01:21:53
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.