ZeroHour

CVE-2025-31140

large

Stored XSS in JetBrains TeamCity Cloud Profiles Page

CVSS 3.1
6.1 medium
EPSS
28%p98
Published
()
Modified
AI analysis

CVE-2025-31140 is a stored cross-site scripting (CWE-79) flaw in JetBrains TeamCity that exists in versions before 2025.03. An attacker can get malicious script content stored in data associated with cloud profiles; when a TeamCity user, such as an administrator, later views the Cloud Profiles page in the web UI, the injected script executes in their browser. Successful exploitation lets the attacker run JavaScript in the context of the victim's session, potentially stealing session tokens or performing actions as that user, with limited confidentiality and integrity impact per the CVSS score (6.1 medium, network vector, no privileges required but user interaction needed). Any organization running an unpatched TeamCity instance whose web UI is reachable by untrusted users is affected. There is no public proof-of-concept, the flaw is not yet in CISA's KEV, and no in-the-wild exploitation is confirmed, though EPSS assigns a high 28% probability of exploitation within 30 days (98th percentile).

What to do: Upgrade TeamCity to version 2025.03 or later, which fixes this flaw. Until patched, restrict which users can view and edit Cloud Profiles, audit stored cloud-profile entries for unexpected script content, and review web UI access controls; no public PoC or KEV listing exists yet, but the elevated EPSS score warrants prompt patching.

Affected
JetBrains TeamCityall versions before 2025.03 (fixed in 2025.03)
Estimated exposure
largeon the order of tens of thousands of TeamCity server installations — Public internet-wide scans such as Shodan and Censys have historically indexed tens of thousands of TeamCity servers, and TeamCity is a widely deployed enterprise CI/CD product, so the unpatched population is plausibly in the 10k-100k…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page

Vendors
jetbrains
Products
teamcity
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.