Reflected XSS Vulnerability in JetBrains TeamCity
CVE-2026-49375

6.1MEDIUM

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-49375?

A reflected XSS vulnerability exists in JetBrains TeamCity versions before 2026.1, allowing attackers to inject malicious scripts via the repository download page. This could lead to unauthorized access or manipulation of user data, posing significant security risks to users accessing this page.

Affected Version(s)

TeamCity 0 < 2026.1, 2025.11.5

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.