Cross-site scripting in YouTrack - CVE-2026-103493
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in Mermaid and LaTeX content rendering when rendering stored user-supplied Mermaid and LaTeX content. A remote user can store crafted Mermaid or LaTeX content to execute arbitrary script in a victim's browser.
User interaction is required for a victim to view the crafted content.