Impact
JetBrains YouTrack versions prior to build 2026.2.17394 let an attacker embed malicious script code into an article title; the title is then inserted into digest emails that are sent to users. When a user opens one of those emails, the embedded script executes in the context of the user’s browser, allowing the attacker to read cookies or session data, block or deface the page, or otherwise perform actions while the user is authenticated.
Affected Systems
The affected product is JetBrains YouTrack. All installations of YouTrack built before build 2026.2.17394 are susceptible. No specific operating system or deployment environment restrictions are noted.
Risk and Exploitability
The CVSS score of 3.5 indicates low overall severity. The EPSS score is reported as <1%, suggesting a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires that an attacker first create or modify an article title in the YouTrack instance, after which the malicious content is included in digest emails sent to users. The vulnerability is only exploitable if a victim opens the email, so it is an email‑based XSS risk rather than a direct web‑app exploit.
OpenCVE Enrichment