REDHAT-BUG-2494110: High severity flatpak/org.freedesktop.portal.OpenURI vulnerability
A local sandbox escape and host information disclosure flaw was found in Yelp. A regression introduced in the companion yelp-xsl stylesheet component targets the gnome-42 and master development branches, leaving the application's Content Security Policy (CSP) style handling directives overly permissive.
A malicious or compromised sandboxed Flatpak application can programmatically abuse the standard host org.freedesktop.portal.OpenURI portal interface to pass crafted help layout files (ghelp:// or mallard extensions). Because the system portal processes this request silently without requiring user interaction, host-level Yelp is automatically invoked to parse the file outside the application container. The attacker-controlled layout leverages local XML inclusions to load arbitrary host-level files into memory, which are subsequently exfiltrated out-of-band to a remote server using a background CSS url() query embedded inside a structured SVG document.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2494110?
The severity of REDHAT-BUG-2494110 is classified as high with a score of 7.
How do I fix REDHAT-BUG-2494110?
To fix REDHAT-BUG-2494110, update the affected packages to the latest version as provided by Red Hat.
What are the implications of REDHAT-BUG-2494110?
REDHAT-BUG-2494110 can lead to a local sandbox escape and unauthorized host information disclosure.
Which components are affected by REDHAT-BUG-2494110?
The components affected by REDHAT-BUG-2494110 include Yelp and the companion yelp-xsl stylesheet in the gnome-42 and master development branches.
When was REDHAT-BUG-2494110 published?
REDHAT-BUG-2494110 was published on June 29, 2026.