VulnerabilityModified
CVE-2025-3155
The Gnome user help application allows the help document to execute arbitrary scripts.
HIGH 7.4EPSS 14.2%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.2%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
- CVSS 3.1
- 7.4 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
- EPSS
- 14.21% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- gnome/yelp · debian/debian linux · redhat/codeready linux builder · redhat/codeready linux builder for arm64 · redhat/codeready linux builder for arm64 eus · redhat/codeready linux builder for eus · redhat/codeready linux builder for ibm z systems · redhat/codeready linux builder for ibm z systems eus · redhat/codeready linux builder for power little endian · redhat/codeready linux builder for power little endian eus · redhat/enterprise linux · redhat/enterprise linux eus · redhat/enterprise linux for arm 64 · redhat/enterprise linux for arm 64 eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux server aus · redhat/enterprise linux server tus · +1 more
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2025:4450Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4451Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4456Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4457Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4532Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7430Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7569Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-3155Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2357091Exploit, Issue Tracking, Third Party Advisory
- https://gitlab.gnome.org/GNOME/yelp/-/issues/221
- http://www.openwall.com/lists/oss-security/2025/04/04/1Mailing List
- https://lists.debian.org/debian-lts-announce/2025/05/msg00036.htmlMailing List
- https://lists.debian.org/debian-lts-announce/2025/05/msg00037.htmlMailing List
- https://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.