CVE-2026-13601
A malicious Flatpak application can open crafted help content through the OpenURI portal.
Does this matter?
Lower severity and a low EPSS score (0.18%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.18% probability · 8th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-693
- Affected
- redhat/enterprise linux · gnome/yelp
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2026:47177
- https://access.redhat.com/errata/RHSA-2026:47178
- https://access.redhat.com/errata/RHSA-2026:54539
- https://access.redhat.com/errata/RHSA-2026:54540
- https://access.redhat.com/errata/RHSA-2026:54605
- https://access.redhat.com/errata/RHSA-2026:54624
- https://access.redhat.com/errata/RHSA-2026:54637
- https://access.redhat.com/errata/RHSA-2026:54666
- https://access.redhat.com/errata/RHSA-2026:57417
- https://access.redhat.com/security/cve/CVE-2026-13601Vendor Advisory
- https://blogs.gnome.org/mcatanzaro/2026/05/11/flatpak-sandbox-escape-via-yelp/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2494110Issue Tracking, Vendor Advisory
- https://gitlab.gnome.org/GNOME/yelp/-/commit/c8c8244c8a812860782d635890c9b6c43ecc2639Patch
- https://gitlab.gnome.org/GNOME/yelp/-/work_items/238Issue Tracking, Mitigation, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2026:47177
- https://access.redhat.com/errata/RHSA-2026:47178
- https://access.redhat.com/errata/RHSA-2026:54539
- https://access.redhat.com/errata/RHSA-2026:54540
- https://access.redhat.com/errata/RHSA-2026:54605
- https://access.redhat.com/errata/RHSA-2026:54624
- https://access.redhat.com/errata/RHSA-2026:54637
- https://access.redhat.com/errata/RHSA-2026:54666
- https://access.redhat.com/errata/RHSA-2026:57417
- https://access.redhat.com/security/cve/CVE-2026-13601Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2494110Issue Tracking, Vendor Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-13601.jsonVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.