Cross-site scripting in YouTrack - CVE-2026-86484
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to improper neutralization of AngularJS template expressions in assignee names when rendering assignee names. A remote attacker can inject a malicious AngularJS template into an assignee name to execute arbitrary script in a victim\'s browser.
User interaction is required to view content containing the affected assignee name.