
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-103497 is a Server-Side Request Forgery (SSRF) vulnerability in JetBrains YouTrack's GitHub VCS integration. It affects all YouTrack versions before 2026.2.19422 and was disclosed on October 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium/Moderate), assigned by JetBrains (GitHub Advisory, JetBrains).
The vulnerability is classified as CWE-918 (Server-Side Request Forgery), where the YouTrack server fails to sufficiently validate or restrict URLs supplied through the GitHub VCS integration before making outbound requests. An authenticated attacker with high privileges (administrator-level) can craft malicious VCS integration configurations to cause the YouTrack server to issue requests to arbitrary internal or external destinations. Because the scope is marked as "Changed," the impact extends beyond the YouTrack application itself to other systems reachable from the server's network position (GitHub Advisory, JetBrains).
Successful exploitation allows an authenticated administrator to cause the YouTrack server to make unauthorized requests to internal network resources, potentially exposing sensitive data (low confidentiality impact) or making limited modifications to systems accessible from the YouTrack server (low integrity impact). Availability is not impacted. The changed scope means internal services behind the YouTrack server's network perimeter — such as metadata services, internal APIs, or other infrastructure — could be probed or partially manipulated (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. Exploitation requires high privileges (administrator access), which significantly limits the attack surface. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. NVD SSVC assessment classifies exploitation as "none" and the attack as non-automatable (GitHub Advisory, JetBrains).
http://169.254.169.254/ for cloud metadata, or an internal service like http://192.168.1.1/admin) in the integration's server/endpoint field.169.254.169.254), or unusual external hosts originating from the VCS integration service.JetBrains has released a fix in YouTrack version 2026.2.19422; upgrading to this version or later is the recommended remediation (JetBrains). As a compensating control, administrators should implement network segmentation and firewall rules to restrict outbound connections from the YouTrack server to only necessary external hosts, blocking access to internal network ranges and cloud metadata services. Additionally, limiting YouTrack administrator access to trusted personnel reduces the risk of exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."