CVE-2025-5471

Uncontrolled Search Path Element vulnerability in Yandex Telemost on MacOS allows Search Order Hijacking.This issue affects Telemost: before 2.19.1.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:yandex:yandex_telemost:*:*:*:*:*:macos:*:*

History

19 Feb 2026, 17:03

Type Values Removed Values Added
First Time Yandex yandex Telemost
Yandex
References () https://yandex.com/bugbounty/i/hall-of-fame-products - () https://yandex.com/bugbounty/i/hall-of-fame-products - Vendor Advisory
CPE cpe:2.3:a:yandex:yandex_telemost:*:*:*:*:*:macos:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

09 Dec 2025, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-09 16:17

Updated : 2026-02-19 17:03


NVD link : CVE-2025-5471

Mitre link : CVE-2025-5471

CVE.ORG link : CVE-2025-5471


JSON object : View

Products Affected

yandex

  • yandex_telemost
CWE
CWE-427

Uncontrolled Search Path Element