DOM-Based XSS Vulnerability in JetBrains TeamCity Affecting Code Inspection Reports
CVE-2025-26493

4.6MEDIUM

Key Information:

Vendor
Jetbrains
Status
Vendor
CVE Published:
11 February 2025

Summary

JetBrains TeamCity versions prior to 2024.12.2 are susceptible to multiple DOM-based Cross-Site Scripting (XSS) vulnerabilities within the Code Inspection Report tab. These vulnerabilities occur due to improper handling of untrusted input, allowing attackers to inject malicious scripts. If exploited, such scripts could execute in the context of the user’s session, potentially leading to data theft or unauthorized actions. Organizations using affected versions should promptly update their software to mitigate these risks and enhance overall security.

Affected Version(s)

TeamCity 0 < 2024.12.2

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.