Impact
The vulnerability is a stored cross‑site scripting flaw that allows an attacker to inject malicious JavaScript into the language label of a JetBrains YouTrack fenced code block. Once the label is stored, any user who views the corresponding code block will have the script executed in their browser, potentially enabling session hijacking, data theft, or defacement. This flaw is classified as CWE‑79.
Affected Systems
JetBrains YouTrack installations running any version prior to 2026.2.18068 are vulnerable because the vulnerability was addressed in that release. All users who can create or edit fenced code blocks with custom language labels are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.2, indicating high severity, and the EPSS score is not available, while it is not listed in the CISA KEV catalog. Exploitation requires a user to view a code block with a malicious language label, which is typically achievable by an attacker who can submit or modify code blocks. The risk is therefore moderate to high, especially in environments where users edit code blocks without stringent access controls.
OpenCVE Enrichment