JetBrains YouTrack Email Spoofing Vulnerability via Administrative API

Vulnerability

A vulnerability allowing email spoofing through an administrative API has been identified in JetBrains YouTrack versions prior to 2025.2.86069, 2024.3.85077, and 2025.1.86199. This issue could be exploited to send emails that appear to come from a different user, potentially leading to unauthorized actions or information disclosure.

Impact

Exploitation of this vulnerability could result in email spoofing, allowing an attacker to send misleading emails that appear to come from a trusted source.

Remediation

Users can update to JetBrains YouTrack versions 2025.2.86069, 2024.3.85077, or 2025.1.86199 to address this vulnerability.

Added: Jul 15, 2025, 5:18 PM
Updated: Jul 15, 2025, 8:32 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
4.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.