DOM-Based XSS Vulnerability in JetBrains TeamCity Affecting Code Inspection Reports
CVE-2025-26493
What is CVE-2025-26493?
JetBrains TeamCity versions prior to 2024.12.2 are susceptible to multiple DOM-based Cross-Site Scripting (XSS) vulnerabilities within the Code Inspection Report tab. These vulnerabilities occur due to improper handling of untrusted input, allowing attackers to inject malicious scripts. If exploited, such scripts could execute in the context of the user’s session, potentially leading to data theft or unauthorized actions. Organizations using affected versions should promptly update their software to mitigate these risks and enhance overall security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
TeamCity 0 < 2024.12.2
References
EPSS Score
11% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved