Executive brief
JetBrains YouTrack is a project tracking and issue management system used by development teams. A stored cross-site scripting (XSS) vulnerability in the Agile board feature allows attackers to inject malicious scripts through custom fields, which could be executed when other team members view the board, potentially compromising their session or stealing sensitive information.
Technical details
The vulnerability is a stored XSS flaw in JetBrains YouTrack's Agile board custom field handling, where user-supplied input is not properly sanitized before being displayed to other users. An attacker with the ability to edit custom fields on Agile board cards can inject malicious JavaScript that persists in the application and executes in the browsers of any user viewing the affected board. This requires authenticated access to YouTrack but no special privileges. The vulnerability has been fixed in YouTrack version 2026.2.18634 and later.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed