SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75048

HIGH · CVSS 8.2 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

JetBrains YouTrack versions prior to 2026.2.18068 are vulnerable to stored cross-site scripting (XSS) attacks due to improper handling of the fenced code-block language label. This vulnerability allows attackers to inject malicious scripts that could be executed in the context of users accessing the affected application, potentially leading to data theft or session hijacking. Organizations using YouTrack should prioritize patching this vulnerability to safeguard their systems and user data.

CVE
CVE-2026-75048
Severity
HIGH
CVSS
8.2
EPSS
0.20%

Original NVD Description

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

Related CVEs

Other vulnerabilities affecting the same vendor(s)