CyberRota Analysis
AI-GeneratedJetBrains YouTrack versions prior to 2026.2.18068 are vulnerable to stored cross-site scripting (XSS) attacks due to improper handling of the fenced code-block language label. This vulnerability allows attackers to inject malicious scripts that could be executed in the context of users accessing the affected application, potentially leading to data theft or session hijacking. Organizations using YouTrack should prioritize patching this vulnerability to safeguard their systems and user data.
CVE
CVE-2026-75048
Severity
HIGH
CVSS
8.2
EPSS
0.20%
Original NVD Description
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Related CVEs
Other vulnerabilities affecting the same vendor(s)