Description
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Published: 2026-07-10
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains YouTrack versions prior to build 2026.2.17394 let an attacker embed malicious script code into an article title; the title is then inserted into digest emails that are sent to users. When a user opens one of those emails, the embedded script executes in the context of the user’s browser, allowing the attacker to read cookies or session data, block or deface the page, or otherwise perform actions while the user is authenticated.

Affected Systems

The affected product is JetBrains YouTrack. All installations of YouTrack built before build 2026.2.17394 are susceptible. No specific operating system or deployment environment restrictions are noted.

Risk and Exploitability

The CVSS score of 3.5 indicates low overall severity. The EPSS score is reported as <1%, suggesting a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires that an attacker first create or modify an article title in the YouTrack instance, after which the malicious content is included in digest emails sent to users. The vulnerability is only exploitable if a victim opens the email, so it is an email‑based XSS risk rather than a direct web‑app exploit.

Generated by OpenCVE AI on July 28, 2026 at 08:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to build 2026.2.17394 or later, which sanitizes article titles before inclusion in digest emails.
  • If an upgrade is not immediately feasible, disable the digest email feature or remove article titles from the email content to prevent the injection of unsanitized data.
  • Configure email clients and gateways to block or strip JavaScript from received messages, and consider implementing email filtering to detect and quarantine suspicious scripts.

Generated by OpenCVE AI on July 28, 2026 at 08:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Email Digests

Sat, 18 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Email Digests

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Digest Emails

Wed, 15 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Digest Emails

Tue, 14 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in JetBrains YouTrack Digest Emails

Mon, 13 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in JetBrains YouTrack Digest Emails

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-10T16:59:33.210Z

Reserved: 2026-07-10T13:56:26.656Z

Link: CVE-2026-61492

cve-icon Vulnrichment

Updated: 2026-07-10T15:14:33.080Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:30:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')