HIGH · 7.4

CVE-2025-3155

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate...

Vulnerability Description

A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.

CVSS Score

7.4

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
GnomeYelp42.2-8
DebianDebian Linux11.0
RedhatCodeready Linux Builder8.0
RedhatCodeready Linux Builder For Arm648.0_aarch64
RedhatCodeready Linux Builder For Arm64 Eus8.8_aarch64
RedhatCodeready Linux Builder For Eus8.8
RedhatCodeready Linux Builder For Ibm Z Systems8.0_s390x
RedhatCodeready Linux Builder For Ibm Z Systems Eus8.8_s390x
RedhatCodeready Linux Builder For Power Little Endian8.0_ppc64le
RedhatCodeready Linux Builder For Power Little Endian Eus8.8_ppc64le
RedhatEnterprise Linux8.0
RedhatEnterprise Linux Eus9.2
RedhatEnterprise Linux For Arm 648.0
RedhatEnterprise Linux For Arm 64 Eus9.4_aarch64
RedhatEnterprise Linux For Ibm Z Systems8.0_s390x
RedhatEnterprise Linux For Ibm Z Systems Eus8.8_s390x
RedhatEnterprise Linux For Power Little Endian8.0_ppc64le
RedhatEnterprise Linux For Power Little Endian Eus8.8_ppc64le
RedhatEnterprise Linux Server Aus8.2
RedhatEnterprise Linux Server Tus8.4

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-3155?

CVE-2025-3155 is a vulnerability with a CVSS score of 7.4 (HIGH). A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate...

How severe is CVE-2025-3155?

CVE-2025-3155 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-3155?

Check the references section above for vendor advisories and patch information. Affected products include: Gnome Yelp, Debian Debian Linux, Redhat Codeready Linux Builder, Redhat Codeready Linux Builder For Arm64, Redhat Codeready Linux Builder For Arm64 Eus.