DOM-Based XSS Vulnerability in JetBrains TeamCity Affecting Code Inspection Reports
CVE-2025-26493
6.1MEDIUM
What is CVE-2025-26493?
JetBrains TeamCity versions prior to 2024.12.2 are susceptible to multiple DOM-based Cross-Site Scripting (XSS) vulnerabilities within the Code Inspection Report tab. These vulnerabilities occur due to improper handling of untrusted input, allowing attackers to inject malicious scripts. If exploited, such scripts could execute in the context of the user’s session, potentially leading to data theft or unauthorized actions. Organizations using affected versions should promptly update their software to mitigate these risks and enhance overall security.
Affected Version(s)
TeamCity 0 < 2024.12.2