REDHAT-BUG-2494110: High severity flatpak/org.freedesktop.portal.OpenURI vulnerability

Published Jun 29, 2026
·
Updated

A local sandbox escape and host information disclosure flaw was found in Yelp. A regression introduced in the companion yelp-xsl stylesheet component targets the gnome-42 and master development branches, leaving the application's Content Security Policy (CSP) style handling directives overly permissive.

A malicious or compromised sandboxed Flatpak application can programmatically abuse the standard host org.freedesktop.portal.OpenURI portal interface to pass crafted help layout files (ghelp:// or mallard extensions). Because the system portal processes this request silently without requiring user interaction, host-level Yelp is automatically invoked to parse the file outside the application container. The attacker-controlled layout leverages local XML inclusions to load arbitrary host-level files into memory, which are subsequently exfiltrated out-of-band to a remote server using a background CSS url() query embedded inside a structured SVG document.

Affected Software

3 affected components
flatpak/org.freedesktop.portal.OpenURI
Flatpak
Yelp Yelp

Event History

Jun 29, 2026
Data Sourced
via Red Hat·08:53 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2494110?

The severity of REDHAT-BUG-2494110 is classified as high with a score of 7.

2

How do I fix REDHAT-BUG-2494110?

To fix REDHAT-BUG-2494110, update the affected packages to the latest version as provided by Red Hat.

3

What are the implications of REDHAT-BUG-2494110?

REDHAT-BUG-2494110 can lead to a local sandbox escape and unauthorized host information disclosure.

4

Which components are affected by REDHAT-BUG-2494110?

The components affected by REDHAT-BUG-2494110 include Yelp and the companion yelp-xsl stylesheet in the gnome-42 and master development branches.

5

When was REDHAT-BUG-2494110 published?

REDHAT-BUG-2494110 was published on June 29, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203