Impact
JetBrains YouTrack allows users to embed Mermaid and LaTeX code within data that is stored on the server; malicious input is not properly sanitized, enabling stored cross‑site scripting. A successful exploit lets an attacker embed arbitrary JavaScript, which executes in the browsers of users who view the affected content, compromising confidentiality, integrity, and availability of user sessions.
Affected Systems
JetBrains YouTrack installations running a version earlier than 2026.2.19422 are impacted. The vulnerability exists in the handling of Mermaid and LaTeX fragments that are persisted in the database and rendered later when a user views the content.
Risk and Exploitability
The CVSS score of 8.1 classifies the vulnerability as High, and the EPSS score is not available but the lack of inclusion in the CISA KEV list does not detract from the severity. Attackers can achieve the exploit by submitting payloads through the standard user interface; the vulnerability is remote and does not require privileged conditions.
OpenCVE Enrichment