Executive brief
JetBrains YouTrack is a project and issue tracking system used by development teams to manage work and collaborate. An attacker with the ability to upload project or organization icons could inject malicious scripts that execute in the browsers of other users viewing those icons, potentially compromising user sessions or stealing sensitive project data.
Technical details
This is a stored cross-site scripting (XSS) vulnerability in JetBrains YouTrack's icon upload functionality for projects and organizations. The vulnerability exists because uploaded icon files are not properly sanitized or validated before being displayed to other users. An authenticated attacker can upload a malicious file as a project or organization icon; the injected script then executes in the context of the victim's browser when they view the affected project or organization. The vulnerability is fixed in YouTrack version 2026.2.18634 and later.
Affected products
- JetBrains YouTrack before 2026.2.18634
Timeline
- 2026-09-07: disclosed
- 2026-09-07: patched: Fixed in version 2026.2.18634