4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate …
In JetBrains YouTrack before 2026.2.18112 an authenticated user could enumerate accounts via the users search endpoint
Affected products
- <2026.2.18112
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
9.1 CRITICAL
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker …
In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature
Affected products
- <2025.3.156085, 2026.1.13913, 2026.2.18112
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only …
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
8.2 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced …
In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible
Affected products
- <2026.2.18068
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
8.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed …
In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint
Affected products
- <2025.3.156085, 2026.1.13914, 2026.2.18095
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and …
In JetBrains YouTrack before 2026.2.18634 iDOR via the watchRules and issueListConfig endpoints exposed private saved searches
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
4.6 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee …
In JetBrains YouTrack before 2026.2.18634 angularJS template injection in assignee names led to stored XSS
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating …
In JetBrains YouTrack before 2026.2.18687 missing permission checks allowed creating knowledge base articles in inaccessible projects
Affected products
- <2026.2.18687
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
3.1 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed …
In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
8.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed …
In JetBrains YouTrack before 2026.2.18788, 2026.1.14055, 2025.3.161254 missing authorisation allowed access to restricted REST API resources via IDOR
Affected products
- <2026.2.18788, 2026.1.14055, 2025.3.161254
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
3.5 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via …
In JetBrains YouTrack before 2026.2.18634 stored XSS was possible via project and organization icon uploads
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
3.7 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler …
In JetBrains YouTrack before 2026.2.18634 the generic VCS webhook handler failed open when its secret was blank
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
5.4 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Changed (C)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom …
In JetBrains YouTrack before 2026.2.18634 stored XSS via a custom field on Agile board cards was possible
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk …
In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
Affected products
- <2026.2.18769
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting …
In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
8.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed …
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
6.8 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): High (H)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): High (H)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without …
In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
Affected products
- <2026.2.18769
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
3.3 LOW
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers …
In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket webhooks
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure …
In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
8.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): High (H)
- Integrity (I): Low (L)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed …
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
7.7 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Changed (C)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Changed (C)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized …
In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse accepted
- @LeSuisse published on GitHub
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user …
In JetBrains YouTrack before 2026.2.18634 an IDOR in the user profile API disclosed private issues and starred folders across organizations
Affected products
- <2026.2.18634
Matching in nixpkgs
pkgs.youtrack
Issue tracking and project management tool for developers
-
nixos-unstable 2026.1.13757
- nixpkgs-unstable 2026.1.13757
- nixos-unstable-small 2026.2.17765
-
nixos-26.05 2026.1.13757
- nixos-26.05-small 2026.2.17765
- nixpkgs-26.05-darwin 2026.1.13757
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>