Impact
Stored XSS via project and organization icon uploads allows an attacker to inject JavaScript that executes with the privileges of any user who views the affected icon. The vulnerability could lead to session hijacking, data theft, or defacement of the user interface. The weakness is a classic stored cross‑site scripting flaw (CWE‑79).
Affected Systems
The flaw exists in JetBrains YouTrack versions prior to 2026.2.18634. All deployments of the product that have not applied the latest release are vulnerable. Organizations using YouTrack for project management and issue tracking are impacted.
Risk and Exploitability
The CVSS score of 3.5 indicates a low severity, and no EPSS data is available. The vulnerability is not part of CISA’s KEV catalog. The attack vector is inferred from the description to be a file upload operation; an attacker must be able to upload an icon that contains malicious script. Once uploaded, any authenticated or even unauthenticated user who views the icon can trigger the payload. Because this is a stored XSS rather than a remote code execution, exploitation requires only the ability to set icon content and observe the page rendering.
OpenCVE Enrichment