Description
In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
Published: 2026-07-10
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains YouTrack renders Mermaid diagrams that allow CSS to be embedded. This flaw, classified as CWE‑1021, can lead to unauthorized style changes within the application’s user interface. An attacker could embed malicious CSS in a diagram to manipulate UI rendering, potentially confusing users or masking interface elements.

Affected Systems

JetBrains YouTrack versions before 2026.2.17012 are affected. No other vendors or products are listed as impacted. The vulnerability applies to all releases older than 2026.2.17012, regardless of minor sub‑versions.

Risk and Exploitability

The CVSS score of 3.5 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The attack vector is likely the submission of a Mermaid diagram containing malicious CSS, which requires the attacker to provide input that is processed as a diagram, typically through user‑generated content or an interface that accepts diagram definitions.

Generated by OpenCVE AI on July 28, 2026 at 08:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.17012 or later.
  • Disable Mermaid diagram rendering if the feature is not required for business processes.
  • If disabling is not feasible, validate and sanitize Mermaid diagram input to remove or neutralize CSS before rendering.

Generated by OpenCVE AI on July 28, 2026 at 08:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title CSS injection via Mermaid diagram rendering in JetBrains YouTrack

Thu, 23 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title CSS injection via Mermaid diagram rendering in JetBrains YouTrack

Tue, 21 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title CSS Injection via Mermaid Diagram Rendering in JetBrains YouTrack

Thu, 16 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title CSS Injection via Mermaid Diagram Rendering in JetBrains YouTrack

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title YouTrack CSS Injection via Mermaid Diagram Rendering

Mon, 13 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title YouTrack CSS Injection via Mermaid Diagram Rendering

Sun, 12 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title CSS Injection via Mermaid Diagram Rendering in JetBrains YouTrack

Sat, 11 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title CSS Injection via Mermaid Diagram Rendering in JetBrains YouTrack

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible
Weaknesses CWE-1021
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-10T17:00:21.132Z

Reserved: 2026-07-07T09:41:06.835Z

Link: CVE-2026-59791

cve-icon Vulnrichment

Updated: 2026-07-10T16:01:09.353Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames