Yelp · Yelp · CVE-2026-13601
**Name of the Vulnerable Software and Affected Versions**
Yelp (affected versions not specified)
**Description**
A flaw exists due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak sandbox isolation. This allows Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests, potentially leading to the unauthorized disclosure of sensitive information.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.