CyberRota
← Ana sayfaya dön

CVE-2026-13601

HIGH · CVSS 7.1 EPSS %0.14

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-29T10:16:30.180 · Çekilme zamanı: 2026-06-30T18:37:04.559312+00:00

CyberRota Yorumu

Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-13601
Severity
HIGH
CVSS
7.1
EPSS
%0.14

Orijinal NVD Açıklaması

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted CSS stylesheet within a structured SVG document, attacker-controlled content can bypass Flatpak's intended sandbox isolation, allowing Yelp to evaluate local XML inclusions and disclose arbitrary user-readable host files through remote CSS resource requests. This may result in the unauthorized disclosure of sensitive information.