SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2025-3155

The Gnome user help application allows the help document to execute arbitrary scripts.

HIGH 7.4EPSS 14.2%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

CVSS 3.1
7.4 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
EPSS
14.21% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-601
Affected
gnome/yelp · debian/debian linux · redhat/codeready linux builder · redhat/codeready linux builder for arm64 · redhat/codeready linux builder for arm64 eus · redhat/codeready linux builder for eus · redhat/codeready linux builder for ibm z systems · redhat/codeready linux builder for ibm z systems eus · redhat/codeready linux builder for power little endian · redhat/codeready linux builder for power little endian eus · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux for arm 64 · redhat/enterprise linux for arm 64 eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux server aus · redhat/enterprise linux server tus · +1 more
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.