Cross-site scripting in YouTrack - CVE-2026-100275
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of script content in the workflow error notification toast when rendering stored workflow error notifications. A remote attacker can store malicious script content in a workflow error notification to execute arbitrary script in a victim's browser.
Exploitation requires a user to view the workflow error notification toast.