CVE-2025-3155
HIGHCVSS 7.4/10EPSS 10.60%
Last modified
CVE-2025-3155 is a high-severity vulnerability rated 7.4/10 on the CVSS scale. A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. EPSS estimates a 10.60% chance of exploitation in the next 30 days.
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Yelp | 42.2-8 |
| Debian | Debian Linux | 11.0 |
| Redhat | Codeready Linux Builder | 8.0 |
| Redhat | Codeready Linux Builder | 9.0 |
| Redhat | Codeready Linux Builder For Arm64 | 8.0_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 | 9.0_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 8.8_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 9.2_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 9.4_aarch64 |
| Redhat | Codeready Linux Builder For Arm64 Eus | 9.6_aarch64 |
| Redhat | Codeready Linux Builder For Eus | 8.8 |
| Redhat | Codeready Linux Builder For Eus | 9.2 |
| Redhat | Codeready Linux Builder For Eus | 9.4 |
| Redhat | Codeready Linux Builder For Ibm Z Systems | 8.0_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems | 9.0_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 8.8_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 9.2_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 9.4_s390x |
| Redhat | Codeready Linux Builder For Ibm Z Systems Eus | 9.6_s390x |
| Redhat | Codeready Linux Builder For Power Little Endian | 8.0_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian | 9.0_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 8.8_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 9.2_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 9.4_ppc64le |
| Redhat | Codeready Linux Builder For Power Little Endian Eus | 9.6_ppc64le |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux | 9.0 |
| Redhat | Enterprise Linux Eus | 9.2 |
| Redhat | Enterprise Linux Eus | 9.4 |
| Redhat | Enterprise Linux Eus | 9.6 |
| Redhat | Enterprise Linux For Arm 64 | 8.0 |
| Redhat | Enterprise Linux For Arm 64 | 8.8_aarch64 |
| Redhat | Enterprise Linux For Arm 64 | 9.0_aarch64 |
| Redhat | Enterprise Linux For Arm 64 | 9.2_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.4_aarch64 |
| Redhat | Enterprise Linux For Arm 64 Eus | 9.6_aarch64 |
| Redhat | Enterprise Linux For Ibm Z Systems | 8.0_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems | 9.0_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 8.8_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.2_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.4_s390x |
| Redhat | Enterprise Linux For Ibm Z Systems Eus | 9.6_s390x |
| Redhat | Enterprise Linux For Power Little Endian | 8.0_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian | 9.0_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 8.8_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 9.2_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 9.4_ppc64le |
| Redhat | Enterprise Linux For Power Little Endian Eus | 9.6_ppc64le |
| Redhat | Enterprise Linux Server Aus | 8.2 |
| Redhat | Enterprise Linux Server Aus | 8.4 |
Showing 50 of 63 affected configurations. See NVD for the full list.
References
- https://access.redhat.com/errata/RHSA-2025:4450Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4451Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4455Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4456Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4457Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4505Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:4532Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7430Third Party Advisory
- https://access.redhat.com/errata/RHSA-2025:7569Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2025-3155Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2357091Exploit, Issue Tracking, Third Party Advisory
- https://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-3155?
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
How severe is CVE-2025-3155?
CVE-2025-3155 has a CVSS score of 7.4/10 (HIGH severity). The EPSS model estimates a 10.60% probability of exploitation in the next 30 days.
How do I fix CVE-2025-3155?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
Are you affected by CVE-2025-3155?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
