CVE-2025-3155
yelp - security update
7.4
HIGH
CVSS 3.1
EPSS 12.6%
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
How to fix CVE-2025-3155
To remediate CVE-2025-3155, upgrade the affected package to a fixed version below.
- Debian/yelp—upgrade to 3.38.3-1+deb11u1 or later
- —upgrade to 3.38.3-1+deb11u1 or later
- —upgrade to 42.2-1+deb12u1 or later
- —upgrade to 3.38.3-1+deb11u1 or later
- —upgrade to 3.38.3-1+deb11u1 or later
- —upgrade to 42.1-2+deb12u1 or later
Is CVE-2025-3155 being exploited?
Moderate — EPSS is 12.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (6)
- from 0, < 3.38.3-1+deb11u1
- from 0, < 3.38.3-1+deb11u1
- from 0, < 42.2-1+deb12u1
- from 0, < 3.38.3-1+deb11u1
- from 0, < 3.38.3-1+deb11u1
- from 0, < 42.1-2+deb12u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N |