Cross-site scripting in YouTrack - CVE-2026-103489
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject HTML into VCS command failure notifications.
The vulnerability exists due to improper neutralization of HTML input in VCS command failure notifications when rendering notification content. A remote attacker can cause a VCS command failure notification containing crafted HTML to be rendered to inject HTML into VCS command failure notifications.