CVE-2025-3155
Publication date 3 April 2025
Last updated 14 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| yelp | 26.04 LTS resolute |
Not affected
|
| 24.04 LTS noble |
Fixed 42.2-1ubuntu0.24.04.1
|
|
| 22.04 LTS jammy |
Fixed 42.1-1ubuntu0.1
|
|
| 20.04 LTS focal |
Fixed 3.36.2-0ubuntu1.1
|
|
| 18.04 LTS bionic |
Fixed 3.26.0-1ubuntu2+esm2
|
|
| 16.04 LTS xenial |
Fixed 3.18.1-1ubuntu4+esm2
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.4 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
References
Related Ubuntu Security Notices (USN)
- USN-7447-1
- Yelp vulnerability
- 23 April 2025
- USN-8756-1
- Yelp vulnerability
- 14 September 2026