Impact
A stored Cross‑Site Scripting flaw exists in JetBrains YouTrack before version 2026.2.18634. An attacker can embed malicious JavaScript into a custom field on Agile board cards; the data is persisted and rendered when other users open the card, potentially allowing arbitrary script execution in the victim's browser.
Affected Systems
JetBrains YouTrack versions older than 2026.2.18634 are affected. The flaw surfaces wherever Agile board cards feature editable custom fields.
Risk and Exploitability
The CVSS base score is 5.4, indicating moderate severity. EPSS data is not provided, and the flaw is absent from the CISA KEV catalog. Based on the description, it is inferred that the exploit requires an authenticated user with permission to edit Agile board custom fields, who can insert malicious scripts that are subsequently executed in the browsers of users who view those cards.
OpenCVE Enrichment