Impact
JetBrains YouTrack renders Mermaid diagrams that allow CSS to be embedded. This flaw, classified as CWE‑1021, can lead to unauthorized style changes within the application’s user interface. An attacker could embed malicious CSS in a diagram to manipulate UI rendering, potentially confusing users or masking interface elements.
Affected Systems
JetBrains YouTrack versions before 2026.2.17012 are affected. No other vendors or products are listed as impacted. The vulnerability applies to all releases older than 2026.2.17012, regardless of minor sub‑versions.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The attack vector is likely the submission of a Mermaid diagram containing malicious CSS, which requires the attacker to provide input that is processed as a diagram, typically through user‑generated content or an interface that accepts diagram definitions.
OpenCVE Enrichment