CVE-2025-3155
HIGHCVSS v3.1: 7.4 · EPSS: 0.1060 (95.2 percentile)
Source data as of:
At a glance
- Severity
- HIGH
- CVSS
- 7.4 v3.1 · NVD
- EPSS
- 0.1060 (95.2 percentile) · FIRST.org
- CISA KEV
- No
- Attack conditions (CVSS vector)
- NetworkNo privileges · Source: NVD Vector
- Affected vendors
- redhat, gnome, debian
- Published
- 2025-04-03 · Modified: 2026-06-25
- References
- Jump to references (8)
CVSS / EPSS / KEV
Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
References
Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.
- Distro https://access.redhat.com/errata/RHSA-2025:4450
- Distro https://access.redhat.com/errata/RHSA-2025:4451
- Distro https://access.redhat.com/errata/RHSA-2025:4455
- Distro https://access.redhat.com/errata/RHSA-2025:4456
- Distro https://access.redhat.com/errata/RHSA-2025:4457
- Distro https://access.redhat.com/errata/RHSA-2025:4505
- Distro https://access.redhat.com/errata/RHSA-2025:4532
- Distro https://access.redhat.com/errata/RHSA-2025:7430