CVE-2025-3155 is a high-severity vulnerability in the Gnome Yelp user help application, affecting Debian, Gnome, and Red Hat. It allows arbitrary script execution through malicious help documents, potentially leading to the exfiltration of user files. With a CVSS score of 7.4, this vulnerability requires user interaction (UI:R) but can be exploited remotely (AV:N) with low complexity (AC:L), resulting in high confidentiality impact (C:H). While no public exploits or KEV entries exist, there is limited community discussion and media coverage, indicating some awareness of this dangerous arbitrary file read vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
42.2-8CPE matchmatch criteria | cpe:2.3:a:gnome:yelp:42.2-8:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:a:redhat:codeready_linux_builder:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:redhat:codeready_linux_builder:9.0:*:*:*:*:*:*:* | ||
8.0_aarch64CPE matchmatch criteria | cpe:2.3:a:redhat:codeready_linux_builder_for_arm64:8.0_aarch64:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.