DOM-Based XSS Vulnerability in JetBrains TeamCity Affecting Code Inspection Reports
CVE-2025-26493
4.6MEDIUM
Summary
JetBrains TeamCity versions prior to 2024.12.2 are susceptible to multiple DOM-based Cross-Site Scripting (XSS) vulnerabilities within the Code Inspection Report tab. These vulnerabilities occur due to improper handling of untrusted input, allowing attackers to inject malicious scripts. If exploited, such scripts could execute in the context of the user’s session, potentially leading to data theft or unauthorized actions. Organizations using affected versions should promptly update their software to mitigate these risks and enhance overall security.
Affected Version(s)
TeamCity 0 < 2024.12.2
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved