Cross-site scripting in YouTrack - CVE-2026-61492
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in article titles when digest emails are rendered. A remote user can create an article with a specially crafted title to execute arbitrary script code in a victim's browser.
User interaction is required because a victim must view a digest email containing the crafted article title.