CVE-2026-103493: XSS
Published Oct 1, 2026
·Updated
In JetBrains YouTrack before 2026.2.19422 stored XSS via Mermaid and LaTeX content was possible
Affected Software
1 affected component
JetBrains YouTrack<2026.2.19422
Event History
Oct 1, 2026
CVE Published
via MITRE·09:15 AM
Data Sourced
via MITRE·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which YouTrack versions are affected?
JetBrains YouTrack versions before 2026.2.19422 are affected. Upgrading to 2026.2.19422 or later addresses the issue.
2
Does exploitation require an authenticated account or special privileges?
The CVSS vector indicates no privileges are required and that exploitation is network-accessible. It also requires user interaction.
3
What is the potential impact if exploitation succeeds?
The vulnerability is rated high severity with high confidentiality and integrity impact. No availability impact is indicated.