What is CVE-2026-75048?
This vulnerability is a Stored XSS flaw in JetBrains YouTrack versions before 2026.2.18068, exploitable via the fenced code-block language label. An attacker can inject malicious JavaScript code that gets executed in the browsers of users viewing the affected content. Systems should be updated immediately to version 2026.2.18068 or later.
Azərbaycanca: Bu boşluq JetBrains YouTrack platformasının 2026.2.18068 versiyasından əvvəlki versiyalarında "fenced code-block" dil etiketində saxlanılan XSS (Stored XSS) zəifliyinə yol açır. Bu o deməkdir ki, təcavüzkar zərərli JavaScript kodunu etiketə daxil edərək, həmin səhifəyə baxan istənilən istifadəçinin brauzerində icra etdirə bilər. Təsirə məruz qalan sistemlər dərhal göstərilən versiyaya və ya daha yenisinə yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of JetBrains YouTrack are affected by CVE-2026-75048?
This Stored XSS vulnerability affects all versions of JetBrains YouTrack prior to version 2026.2.18068.
Where can an attacker inject malicious code when exploiting CVE-2026-75048?
An attacker can inject malicious JavaScript code into the fenced code-block language label.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.