
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-59791 is a CSS injection vulnerability in JetBrains YouTrack that allows injection of malicious CSS via Mermaid diagram rendering. It affects all YouTrack versions before 2026.2.17012 and was published on July 10, 2026. The vulnerability carries a CVSS v3.1 base score of 3.5 (Low), assigned by JetBrains (GitHub Advisory, JetBrains).
The root cause is improper restriction of rendered UI layers or frames (CWE-1021), specifically arising from insufficient sanitization of Mermaid diagram input before rendering. An authenticated attacker with low privileges can craft a malicious Mermaid diagram containing injected CSS, which is then rendered in the context of a victim's browser session when they view the diagram. Exploitation requires user interaction — a victim must view the attacker-controlled diagram — and the attack is delivered over the network (GitHub Advisory, JetBrains).
Successful exploitation results in a low integrity impact with no confidentiality or availability impact. An attacker could manipulate the visual appearance of the YouTrack interface for a victim user, potentially enabling UI redressing or misleading interface elements (e.g., fake login prompts or clickjacking overlays). The scope is unchanged, meaning the impact is confined to the vulnerable YouTrack component and does not extend to other systems (GitHub Advisory).
style directives with external URLs or unusual visual overrides).JetBrains has released a fix in YouTrack version 2026.2.17012, which resolves the CSS injection via Mermaid diagram rendering. Organizations should upgrade to version 2026.2.17012 or later as the primary remediation. No specific configuration-based workaround has been published; upgrading is the recommended action (JetBrains, GitHub Advisory).
Security news outlets including GBHackers, CyberSecurityNews, HealSecurity, and VPNCentral covered this vulnerability as part of broader reporting on JetBrains patching six vulnerabilities across IntelliJ IDEA, TeamCity, and YouTrack in July 2026 (GBHackers, CyberSecurityNews, VPNCentral). Coverage was largely informational, noting the low severity of this particular CVE relative to others in the same patch batch. No notable researcher commentary or significant community debate was observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."