PT-2025-26599 · Jetbrains · Teamcity
CVE-2025-52876
·
Published
2025-06-23
·
Updated
2026-08-24
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
JetBrains TeamCity versions prior to 2025.03.3
Description
JetBrains TeamCity is affected by a reflected Cross-Site Scripting (XSS) issue on the favoriteIcon page. This occurs because the application fails to properly protect the web page structure, allowing a remote attacker to execute malicious scripts in the context of a user's session.
Recommendations
Update to version 2025.03.3.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamcity