CVE-2025-3155 – Yelp Gnome User Help Arbitrary Script Execution Vulnerability

The following table lists the changes that have been made to the
CVE-2025-3155 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 03, 2025

    Action Type Old Value New Value
    Added Description A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
    Added CWE CWE-829
    Added Reference https://access.redhat.com/security/cve/CVE-2025-3155
    Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=2357091
Share the Post:

Related Posts