Description
In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Published: 2026-07-10
Score: 3.5 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

JetBrains YouTrack versions built before 2026.2.17394 allow an attacker to inject malicious script code into an article title. The title is then incorporated into digest emails that are sent to users. When a recipient opens the email, the embedded script runs in the user’s browser, enabling the attacker to read browser cookies or session data, deface the page, or perform other actions while the user is authenticated.

Affected Systems

All JetBrains YouTrack installations whose build number is earlier than 2026.2.17394 are affected. The vulnerability applies across all operating systems and deployment environments; only the build version distinguishes vulnerable from patched instances.

Risk and Exploitability

The CVSS score of 3.5 indicates a low overall severity. The EPSS score of <1% suggests exploitation in the wild is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to create or edit an article title in the YouTrack instance, after which the bad content is included in digest emails. The vulnerability is only exploitable if a user opens the email, making it an email‑based XSS risk rather than a direct web‑app exploitation.

Generated by OpenCVE AI on August 1, 2026 at 12:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to JetBrains YouTrack build 2026.2.17394 or newer, which sanitizes article titles before inclusion in digest emails.
  • If an upgrade cannot be performed immediately, consider disabling the digest email feature or configuring the system to exclude article titles from email content to stop the injection of unsanitized data.
  • Apply email client or gateway filtering to strip or block JavaScript in received messages to mitigate potential XSS execution.

Generated by OpenCVE AI on August 1, 2026 at 12:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via article titles in digest emails in JetBrains YouTrack

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Email Digests

Sat, 18 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Email Digests

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Digest Emails

Wed, 15 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in YouTrack Digest Emails

Tue, 14 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in JetBrains YouTrack Digest Emails

Mon, 13 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Stored XSS via Article Titles in JetBrains YouTrack Digest Emails

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-07-10T16:59:33.210Z

Reserved: 2026-07-10T13:56:26.656Z

Link: CVE-2026-61492

cve-icon Vulnrichment

Updated: 2026-07-10T15:14:33.080Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-10T15:16:51.153

Modified: 2026-07-10T18:57:39.147

Link: CVE-2026-61492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T12:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')