ZeroHour

CVE-2025-46618

moderate

Stored XSS on Data Directory tab in JetBrains TeamCity before 2025.03.1

CVSS 3.1
6.1 medium
EPSS
62%p99
Published
()
Modified
AI analysis

CVE-2025-46618 is a stored cross-site scripting (CWE-79) flaw in JetBrains TeamCity, where attacker-supplied content can be persisted and then executed when a user views the Data Directory tab. Per the CVSS vector, the attack is network-based, requires no privileges, and relies on user interaction (UI:R), meaning a victim must load the affected tab for the injected script to run. Because the scope is changed (S:C), the script executes in the victim's browser session within TeamCity, yielding limited confidentiality and integrity impact (CVSS 6.1, medium), such as acting or reading data with the victim's privileges while the tab is viewed. Any TeamCity deployment running a version before 2025.03.1 is affected, and the fix is included in 2025.03.1. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the EPSS score of 61.7% (99th percentile) indicates a high probability of exploitation within the next 30 days.

What to do: Upgrade TeamCity to 2025.03.1 or later as soon as possible and prioritize this given the elevated EPSS score. Until patched, restrict access to the administration area and Data Directory tab to trusted users and check the data directory for unexpected or suspicious uploaded content. Monitor TeamCity logs and JetBrains advisories for signs of exploitation.

Affected
JetBrains TeamCityAll versions before 2025.03.1 (fixed in 2025.03.1)
Estimated exposure
moderate≈ tens of thousands of TeamCity server installations, of which several thousand are internet-exposed (exact install counts unpublished) — Public internet scans conducted during prior TeamCity vulnerability campaigns (e.g., the 2024 auth-bypass mass exploitation) identified thousands of exposed TeamCity servers, and TeamCity's wide enterprise CI/CD deployment footprint…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

Vendors
jetbrains
Products
teamcity
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.