Opened 5 months ago
Closed 4 months ago
#23258 closed enhancement (fixed)
yelp-49.1
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (8)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
comment:3 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
I'm going to reassign these to the book for now so whoever wants to do them can do them.
In the meantime I will continue working on rivendell, but I do not want to continue holding the project back on important issues.
comment:5 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:6 by , 4 months ago
| Priority: | normal → elevated |
|---|
49.1 ==== * Fixed issue that could allow remoate access to local files * Updated translations:
This contains a fix for https://gitlab.gnome.org/GNOME/yelp/-/work_items/238 - which allows for remote data exfiltration via malicious help files. Additional details in https://blogs.gnome.org/mcatanzaro/2026/05/11/flatpak-sandbox-escape-via-yelp/ - and unfortunately no CVE has been assigned still a month later. The mention of Flatpak here doesn't mean much since non-sandboxed applications can abuse this to retrieve data anyway through the same attack vector utilizing the OpenURI portal. This is a repeat of https://gitlab.gnome.org/GNOME/yelp/-/work_items/221
comment:7 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at 3b06750c79dd581b26c74c75ad66cbd0ed6a69c7
Reassigning to SecurityAdvisory for an advisory to be filed.

Accepted per Bruce's recommendation