CVE-2025-3155
Is CVE-2025-3155 real, exploitable, or a false positive? Here's the community verdict.
Community verdict: No field verdicts yet. Be the first practitioner to weigh in.
signals
public sources
Moderate signals. Triage by your actual exposure and reachability.
cisa ssvc
CISA Vulnrichment · assessed
CISA decision, by how critical the affected system is to you:
- low impact → Track
- medium impact → Track
- high impact → Track*
Track: normal patch cycle · Track*: watch closely · Attend: patch sooner · Act: patch now. About SSVC ↗
baseline read
auto · not a community verdict
Low signal — verdict needed
Few public signals point to active risk. Whether a scanner hit here is a true or false positive depends on your version and config — community verdicts decide.
Based on CVSS · FIRST EPSS
Confirm or dispute →CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment.
References
Published
Embed this verdict
[](https://www.truepositive.app/cve/CVE-2025-3155)<a href="https://www.truepositive.app/cve/CVE-2025-3155"><img src="https://www.truepositive.app/cve/CVE-2025-3155/badge.svg" alt="TruePositive verdict for CVE-2025-3155"></a>Live badge that updates automatically as the community verdict changes.
Community ground truth
Be the first practitioner to weigh in
So far this is only TruePositive's editorial baseline from public sources. Add your real-world verdict below — it becomes the signal the next person triaging this relies on.
🥇 The first 50 practitioners to contribute earn a Founding Contributor badge.
In your experience, is this finding real and exploitable?
awaiting field verdictsCurated baseline: A curated baseline from public sources, shown separately from community verdicts.
No account needed. Anonymous verdicts post as an unverified signal. Log in to make yours verified and earn reputation.
Field notes & remediation
Verdicts are the quick signal. Notes are the evidence and fixes behind them.
- 0
No confirmed in-the-wild exploitation or public exploit was found for this yet. FIRST EPSS estimates about a 13% chance of exploitation in the next 30 days, which is high relative to most CVEs. It is reachable over the network with no authentication.
Add a field note or remediationoptional
Related CVEs
Same weakness: CWE-601.
- CVE-2021-38000MED 6.1KEVEPSS 5%
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
- CVE-2012-0518MED 4.7KEVEPSS 5%
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.
- CVE-2021-31879MED 6.1EPSS 1%
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
- CVE-2026-51564MED 4.9EPSS 0%
An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.