CVE-2025-3155
PoC ×2—CVSS 3.1
7.4 high
EPSS
14%p96
Published
()
Modified
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
- Vendors
- gnomedebianredhat
- Products
- yelp, debian linux, codeready linux builder, codeready linux builder for arm64, codeready linux builder for arm64 eus, codeready linux builder for eus, codeready linux builder for ibm z systems, codeready linux builder for ibm z systems eus, codeready linux builder for power little endian, codeready linux builder for power little endian eus, enterprise linux, enterprise linux eus
- Weakness
- CWE-601
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.