Executive brief
JetBrains YouTrack, a project management and issue tracking tool, was vulnerable to a security flaw in its notification template system. An attacker with basic user permissions could inject malicious scripts that would execute in the browsers of other users, including administrators. This could lead to unauthorized access to sensitive project data, session hijacking, or the performance of actions on behalf of other users.
Technical details
A stored cross-site scripting (XSS) vulnerability (CWE-79) existed in JetBrains YouTrack before version 2026.1.13162. The flaw was located in the project notification templates component, where input was not properly neutralized before being rendered in the web interface. An authenticated attacker with low privileges could inject malicious scripts into these templates. When other users, such as project managers or administrators, view or interact with these notifications, the script executes in their browser context. This can lead to full session compromise or unauthorized data exfiltration. The issue has been addressed in version 2026.1.13162.
Affected products
- JetBrains YouTrack before 2026.1.13162
Timeline
- 2026-05-29: advisory: CVE-2026-49368 published by JetBrains
- 2026-05-29: patched: Fixed in version 2026.1.13162