Cross-site scripting in YouTrack - CVE-2026-49368
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in project notification templates when rendering stored template content. A remote user can inject a malicious script into a notification template to execute arbitrary script code in a victim's browser.