CVE-2026-86484CWE-79

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

Medium · published September 7, 2026

CVSS v3.1
4.6
EPSS
In the wild
Unconfirmed
What it is

In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS

The record
Technical detail
CVSS v3.1
4.6 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
Not scored
Weakness
CWE-79 · Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Published
2026-09-07T16:26Z
Timeline
  • 07 SEP 16:26Z
    In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
    cvelistv5