Description
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Published: 2026-08-17
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into the language label of a JetBrains YouTrack fenced code block. Once the label is stored, any user who views the corresponding code block will have the script executed in their browser, potentially enabling session hijacking, data theft, or defacement. This flaw is classified as CWE‑79.

Affected Systems

JetBrains YouTrack installations running any version prior to 2026.2.18068 are vulnerable because the vulnerability was addressed in that release. All users who can create or edit fenced code blocks with custom language labels are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.2, indicating high severity, and the EPSS score is not available, while it is not listed in the CISA KEV catalog. Exploitation requires a user to view a code block with a malicious language label, which is typically achievable by an attacker who can submit or modify code blocks. The risk is therefore moderate to high, especially in environments where users edit code blocks without stringent access controls.

Generated by OpenCVE AI on August 17, 2026 at 17:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade JetBrains YouTrack to version 2026.2.18068 or a later release that includes the fix
  • Limit editing privileges for fenced code blocks until the update is applied
  • Audit existing code blocks for suspicious language labels and cleanse any that contain malicious scripts

Generated by OpenCVE AI on August 17, 2026 at 17:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Title Stored XSS via Code‑Block Language Label in JetBrains YouTrack

Mon, 17 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Jetbrains
Jetbrains youtrack
Vendors & Products Jetbrains
Jetbrains youtrack

Mon, 17 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Jetbrains Youtrack
cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-08-17T16:16:33.192Z

Reserved: 2026-08-17T15:34:07.703Z

Link: CVE-2026-75048

cve-icon Vulnrichment

Updated: 2026-08-17T16:16:27.617Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-17T16:17:51.870

Modified: 2026-08-28T21:29:30.987

Link: CVE-2026-75048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T18:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')