DOM-Based XSS Vulnerability in JetBrains TeamCity Affecting Code Inspection Reports
CVE-2025-26493

6.1MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
11 February 2025

What is CVE-2025-26493?

JetBrains TeamCity versions prior to 2024.12.2 are susceptible to multiple DOM-based Cross-Site Scripting (XSS) vulnerabilities within the Code Inspection Report tab. These vulnerabilities occur due to improper handling of untrusted input, allowing attackers to inject malicious scripts. If exploited, such scripts could execute in the context of the user’s session, potentially leading to data theft or unauthorized actions. Organizations using affected versions should promptly update their software to mitigate these risks and enhance overall security.

Affected Version(s)

TeamCity 0 < 2024.12.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-26493 : DOM-Based XSS Vulnerability in JetBrains TeamCity Affecting Code Inspection Reports