Junglewise Threat Intelligence

CVE-2026-61492: JetBrains YouTrack stored XSS in digest email article titles

CVE-2026-61492 · Severity: low · CVSS 3.5 · Published 2026-07-10

Technologies: Jetbrains YouTrack. Vendors: Jetbrains.

Executive brief

JetBrains YouTrack, a project management and issue tracking tool, was vulnerable to a security flaw where malicious code could be embedded in article titles. This code could then be executed when users viewed digest emails containing those titles. While the impact is limited, it could potentially allow an attacker to access sensitive information within the context of the user's session.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in JetBrains YouTrack versions prior to 2026.2.17394. The flaw is rooted in the improper neutralization of input within article titles (CWE-79), which are subsequently rendered in digest emails. An authenticated attacker with low privileges can inject malicious scripts into an article title. When a victim views a digest email containing the compromised title, the script executes in the victim's browser. This can lead to limited information disclosure. The issue has been addressed in version 2026.2.17394.

Affected products

  • JetBrains YouTrack before 2026.2.17394

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats