Executive brief
JetBrains YouTrack, a project management and issue tracking tool, contained a vulnerability in its web sandboxing component. An attacker with low-level access could potentially manipulate internal software properties, though the complexity of the attack and the requirement for user interaction make it a low-risk issue. This could lead to minor functional disruptions or unauthorized changes to how the application processes data.
Technical details
A prototype pollution vulnerability (CWE-1321) exists in the JetBrains YouTrack 'websandbox bridge' component. The flaw allows an authenticated attacker with low privileges to inject properties into the global JavaScript object prototype. Exploitation requires network access, high attack complexity, and user interaction. Successful exploitation could allow an attacker to modify the behavior of the application's JavaScript environment, potentially leading to unauthorized data modification or logic bypasses. The issue is fixed in YouTrack version 2026.2.16593.
Affected products
- JetBrains YouTrack before 2026.2.16593
Timeline
- 2026-06-26: disclosed
- 2026-06-26: advisory