A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.
{
"cna_assigner": "redhat",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/13xxx/CVE-2026-13601.json",
"cwe_ids": [
"CWE-693"
]
}{
"cpe": "cpe:2.3:a:gnome:yelp:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "49.1"
}
]
}"2026-08-05T09:31:48Z"
[
{
"source": "https://gitlab.gnome.org/gnome/yelp@c8c8244c8a812860782d635890c9b6c43ecc2639",
"id": "CVE-2026-13601-147aa4e4",
"target": {
"file": "libyelp/web-process-extension/yelp-web-process-extension.c"
},
"signature_version": "v1",
"digest": {
"line_hashes": [
"202354764216834693225946491373317686955",
"221356364747779140128725726912119843842",
"108316167307051501293823318469634659420"
],
"threshold": 0.9
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://gitlab.gnome.org/gnome/yelp@c8c8244c8a812860782d635890c9b6c43ecc2639",
"id": "CVE-2026-13601-be2bdbd1",
"target": {
"file": "libyelp/web-process-extension/yelp-web-process-extension.c",
"function": "web_page_send_request"
},
"signature_version": "v1",
"digest": {
"function_hash": "163413263158110910690720703889758726555",
"length": 412.0
},
"signature_type": "Function",
"deprecated": false
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-13601.json"