Impact
JetBrains YouTrack before version 2026.2.19422 contains an HTML injection flaw in VCS command failure notifications. The flaw allows an attacker to inject arbitrary HTML into the notification payload, which is rendered by the client browser. If the malicious content is delivered to a user who views the notification, it can execute script in the user’s browser context, potentially leading to data theft, session hijacking, or phishing attempts. The weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects JetBrains YouTrack software running any version prior to 2026.2.19422. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 2.0 indicates a low‑severity issue, and the EPSS score is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. The attack vector involves a VCS command that fails and triggers a notification; thus, an attacker would need to cause such a failure and convince a user to view the resulting notification, making exploitation relatively constrained compared to local or remote code execution flaws.
OpenCVE Enrichment