VOOZH about

URL: https://www.phoronix.com/news/GNOME-Help-Viewer-2026-Sandbox

⇱ GNOME's Help Viewer Updated Due To Flatpak Sandbox Escape Vulnerability - Phoronix


👁 Phoronix

GNOME's Help Viewer Updated Due To Flatpak Sandbox Escape Vulnerability

Written by Michael Larabel in GNOME on 11 May 2026 at 10:36 AM EDT. 21 Comments
GNOME's help viewer, Yelp, last year was impacted by a serious security issue for arbitrary file reads. There's a new vulnerability affecting the GNOME help viewer that led to the Yelp 49.1 release to address a possible Flatpak sandbox escape vector.

Thanks to funding provided by Germany's Sovereign Tech Agency with its Sovereign Tech Resilience program, Codean Labs was performing a security audit of Flatpak and various GNOME projects. In turn a significant Flatpak sandbox escape was discovered, related to last year's CVE.

GNOME developer Michael Catanzaro explained of this issue that is now fixed in Yelp 49.1:
"In this case, a sandboxed application may launch Yelp to open a malicious help file. The help file can then exfiltrate arbitrary files from your host OS to a web server by using a CSS stylesheet embedded in an SVG. Suffice to say the attack is pretty clever, and certainly more impactful than the typical boring memory safety bugs I more commonly see."

The issue was originally reported three months ago by Codean Labs due to Flatpak applications being able to exfilitrate host files over Yelp's Content Security Policy (CSP) being too permissive.

👁 example


Yelp 49.1 is now available with this fix.

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.