Impact
In JetBrains YouTrack versions before 2026.2.18634, assignee names are rendered using AngularJS templates without proper sanitization, which allows an attacker to inject malicious code that is stored and executed when the page is viewed. The flaw results in stored Cross‑Site Scripting, enabling the attacker to run arbitrary scripts in the victim’s browser context, potentially leading to credential theft, session hijacking, or site defacement where the attacker’s code executes when any user views an issue that contains the malicious assignee name. The weakness is identified as CWE‑79, an injection flaw that allows template code to be interpreted.
Affected Systems
The vulnerability affects JetBrains’ YouTrack product prior to release 2026.2.18634. All deployments of YouTrack that have not applied the 2026.2.18634 patch or newer versions are potentially exposed. No additional affected products or vendors are listed.
Risk and Exploitability
The CVSS score of 4.6 indicates the flaw is of moderate severity. No EPSS score is available, but the lack of a KEV listing suggests no known widespread exploitation yet. The attack vector is inferred to be local or user‑initiated; an attacker must supply a malicious assignee name, which is stored and later rendered to users who view the issue. Therefore, the risk is moderate, with exploitation likely limited to users who can edit or assign issues and later view them.
OpenCVE Enrichment