Executive brief
JetBrains YouTrack, a project management and issue tracking tool, was vulnerable to a security flaw where malicious code could be embedded in article titles. This code could then be executed when users viewed digest emails containing those titles. While the impact is limited, it could potentially allow an attacker to access sensitive information within the context of the user's session.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in JetBrains YouTrack versions prior to 2026.2.17394. The flaw is rooted in the improper neutralization of input within article titles (CWE-79), which are subsequently rendered in digest emails. An authenticated attacker with low privileges can inject malicious scripts into an article title. When a victim views a digest email containing the compromised title, the script executes in the victim's browser. This can lead to limited information disclosure. The issue has been addressed in version 2026.2.17394.
Affected products
- JetBrains YouTrack before 2026.2.17394
Timeline
- 2026-07-10: disclosed
- 2026-07-10: advisory