CVE-2025-53959
7.6JetBrains · YouTrack
JetBrains YouTrack is susceptible to an email spoofing vulnerability via an administrative API, which may allow authenticated users to send unauthorized communications.
Executive summary
JetBrains YouTrack contains an email spoofing vulnerability in its administrative API that could allow an authenticated user to perform unauthorized actions.
Vulnerability
This is a missing authorization vulnerability (CWE-862) occurring within an administrative API. The vulnerability requires the attacker to have low-level privileges (authenticated user) and involves a cross-site request forgery component (UI:R).
Business impact
The ability to spoof emails from a trusted administrative source poses a significant risk to organizational integrity and reputation. Attackers could leverage this flaw to conduct phishing campaigns or social engineering attacks against internal staff or external clients, potentially leading to further credential theft or unauthorized access. Given the CVSS score of 7.6, this vulnerability is classified as High severity.
Remediation
Immediate Action: Upgrade JetBrains YouTrack instances to the fixed versions (2025.2.86069, 2024.3.85077, or 2025.1.86199) as provided by the vendor.
Proactive Monitoring: Review administrative API usage logs for unusual patterns or requests originating from non-administrative user accounts.
Compensating Controls: Implement strict network access controls for the YouTrack administrative interface to limit exposure to trusted management segments.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should prioritize patching this vulnerability during the next scheduled maintenance window. Although the vulnerability requires authentication, the potential for email spoofing represents a material risk to communication security that should be addressed by applying the vendor-provided updates immediately.