A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
3.16.1-1ubuntu13.16.1-1ubuntu23.18.1-1ubuntu23.18.1-1ubuntu33.18.1-1ubuntu43.26.0-1ubuntu13.26.0-1ubuntu23.34.0-13.36.0-13.36.2-0ubuntu13.36.2-0ubuntu1.140.stable-1build141.1-141.2-142.0-142.1-142.1-1ubuntu0.142~beta-242.2-142.2-1build142.2-1build242.2-1ubuntu0.24.04.142.2-242.2-442.2-4build142.3-142.3-3ubuntu142.3-3ubuntu149.0-449.0-5Exploitability
AV:LAC:LPR:LUI:NScope
S:CImpact
C:HI:NA:NCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N