CVE-2025-31140
largeStored XSS in JetBrains TeamCity Cloud Profiles Page
CVE-2025-31140 is a stored cross-site scripting (CWE-79) flaw in JetBrains TeamCity that exists in versions before 2025.03. An attacker can get malicious script content stored in data associated with cloud profiles; when a TeamCity user, such as an administrator, later views the Cloud Profiles page in the web UI, the injected script executes in their browser. Successful exploitation lets the attacker run JavaScript in the context of the victim's session, potentially stealing session tokens or performing actions as that user, with limited confidentiality and integrity impact per the CVSS score (6.1 medium, network vector, no privileges required but user interaction needed). Any organization running an unpatched TeamCity instance whose web UI is reachable by untrusted users is affected. There is no public proof-of-concept, the flaw is not yet in CISA's KEV, and no in-the-wild exploitation is confirmed, though EPSS assigns a high 28% probability of exploitation within 30 days (98th percentile).
What to do: Upgrade TeamCity to version 2025.03 or later, which fixes this flaw. Until patched, restrict which users can view and edit Cloud Profiles, audit stored cloud-profile entries for unexpected script content, and review web UI access controls; no public PoC or KEV listing exists yet, but the elevated EPSS score warrants prompt patching.
| JetBrains TeamCity | all versions before 2025.03 (fixed in 2025.03) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page
- Vendors
- jetbrains
- Products
- teamcity
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.