yelp vulnerabilities
CVEs whose affected-version data names the yelp package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-13601High· 7.1A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open crafted help content through the OpenURI portal. By embedding an untrusted C…
▾ Twilightgnome · yelpEPSS 0.18%via NVD
CVE-2025-3155High· 7.4A flaw was found in Yelp
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
▾ Twilightgnome · yelpEPSS 14%via NVD