CVE-2026-59791
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-59791 is a CSS injection vulnerability in JetBrains YouTrack that allows injection of malicious CSS via Mermaid diagram rendering. It affects all YouTrack versions before 2026.2.17012 and was published on July 10, 2026. The vulnerability carries a CVSS v3.1 base score of 3.5 (Low), assigned by JetBrains (GitHub Advisory, JetBrains).

Technical details

The root cause is improper restriction of rendered UI layers or frames (CWE-1021), specifically arising from insufficient sanitization of Mermaid diagram input before rendering. An authenticated attacker with low privileges can craft a malicious Mermaid diagram containing injected CSS, which is then rendered in the context of a victim's browser session when they view the diagram. Exploitation requires user interaction — a victim must view the attacker-controlled diagram — and the attack is delivered over the network (GitHub Advisory, JetBrains).

Impact

Successful exploitation results in a low integrity impact with no confidentiality or availability impact. An attacker could manipulate the visual appearance of the YouTrack interface for a victim user, potentially enabling UI redressing or misleading interface elements (e.g., fake login prompts or clickjacking overlays). The scope is unchanged, meaning the impact is confined to the vulnerable YouTrack component and does not extend to other systems (GitHub Advisory).

Exploitation steps

  1. Authenticate: Log in to a vulnerable JetBrains YouTrack instance (any version before 2026.2.17012) with a low-privileged user account.
  2. Craft malicious Mermaid diagram: Create a YouTrack issue or wiki page containing a Mermaid diagram block with embedded CSS injection payload (e.g., using Mermaid's styling syntax to inject arbitrary CSS rules).
  3. Deliver to victim: Share the issue or page link with a target user who has access to the YouTrack instance, or post it in a shared project space.
  4. Victim renders the diagram: When the victim views the page, the injected CSS is rendered in their browser, potentially altering the visual appearance of the UI — for example, overlaying fake UI elements, hiding legitimate content, or facilitating clickjacking-style attacks (GitHub Advisory).

Indicators of compromise

  • Logs: YouTrack application logs showing creation or editing of issues/wiki pages containing Mermaid diagram blocks with unusual CSS syntax by low-privileged users.
  • Network: Browser developer tool network traces showing unexpected CSS being loaded or applied from within Mermaid-rendered diagram content.
  • Application: Presence of YouTrack issues or pages with Mermaid diagram blocks containing CSS property injections (e.g., style directives with external URLs or unusual visual overrides).

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2026.2.17012, which resolves the CSS injection via Mermaid diagram rendering. Organizations should upgrade to version 2026.2.17012 or later as the primary remediation. No specific configuration-based workaround has been published; upgrading is the recommended action (JetBrains, GitHub Advisory).

Community reactions

Security news outlets including GBHackers, CyberSecurityNews, HealSecurity, and VPNCentral covered this vulnerability as part of broader reporting on JetBrains patching six vulnerabilities across IntelliJ IDEA, TeamCity, and YouTrack in July 2026 (GBHackers, CyberSecurityNews, VPNCentral). Coverage was largely informational, noting the low severity of this particular CVE relative to others in the same patch batch. No notable researcher commentary or significant community debate was observed.

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57926CRITICAL9.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJun 26, 2026
CVE-2026-61492MEDIUM6.1
  • YouTrack logoYouTrack
  • youtrack
NoYesJul 10, 2026
CVE-2026-57925MEDIUM5.3
  • YouTrack logoYouTrack
  • youtrack
NoYesJun 26, 2026
CVE-2026-57924MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJun 26, 2026
CVE-2026-59791LOW3.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management