CVE-2026-103489Low· 2.0▾ SunlitIn JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
▾ Sunlit zone — Low / medium · no exploitation signal
impact 11 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
In JetBrains YouTrack before 2026.2.19422 hTML injection in VCS command failure notifications was possible
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-103493High· 8.1In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
CVE-2026-100275Medium· 6.9In JetBrains YouTrack before 2026.2.19197 stored XSS in the workflow error notification toast was possible
CVE-2026-100263Medium· 4.7In JetBrains YouTrack before 2026.2.18991 stored HTML injection via the User-Agent header was possible
CVE-2026-86483Medium· 5.4In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
CVE-2026-86484Medium· 4.6In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
CVE-2026-86491Low· 3.5In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads