AngularJS Template Injection in JetBrains YouTrack by JetBrains
CVE-2026-86484
4.6MEDIUM
What is CVE-2026-86484?
In JetBrains YouTrack prior to version 2026.2.18634, a vulnerability exists that permits an AngularJS template injection through manipulated assignee names. This weakness can lead to stored cross-site scripting (XSS) attacks, potentially allowing attackers to execute arbitrary scripts in the context of users accessing the affected instances.
Affected Version(s)
YouTrack 0 < 2026.2.18634