CVE-2025-3155

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Apr 3, 2025
Updated: Apr 16, 2025
CWE ID 829

Summary

CVE-2025-3155 is a newly disclosed vulnerability affecting Yelp. This issue lies in the Gnome user help application, which unintentionally permits the execution of arbitrary scripts within help documents. Malicious actors can exploit this weakness by providing malicious help documents, leading to potential data exfiltration from affected systems. This flaw poses a significant risk, especially in enterprise environments where help files are commonly shared or accessed from untrusted sources. Users are advised to update their systems as soon as patches become available to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share