Impact
JetBrains YouTrack versions built before 2026.2.17394 allow an attacker to inject malicious script code into an article title. The title is then incorporated into digest emails that are sent to users. When a recipient opens the email, the embedded script runs in the user’s browser, enabling the attacker to read browser cookies or session data, deface the page, or perform other actions while the user is authenticated.
Affected Systems
All JetBrains YouTrack installations whose build number is earlier than 2026.2.17394 are affected. The vulnerability applies across all operating systems and deployment environments; only the build version distinguishes vulnerable from patched instances.
Risk and Exploitability
The CVSS score of 3.5 indicates a low overall severity. The EPSS score of <1% suggests exploitation in the wild is unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to create or edit an article title in the YouTrack instance, after which the bad content is included in digest emails. The vulnerability is only exploitable if a user opens the email, making it an email‑based XSS risk rather than a direct web‑app exploitation.
OpenCVE Enrichment