HTML Injection Vulnerability in JetBrains YouTrack
CVE-2026-103489

2LOW

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103489?

An HTML injection vulnerability has been identified in JetBrains YouTrack, specifically related to VCS command failure notifications. This issue affects versions prior to 2026.2.19422, allowing attackers to inject malicious HTML content, potentially compromising the integrity of user data and the overall security of the application.

Affected Version(s)

YouTrack 0 < 2026.2.19422

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.