CVE-2025-46618
moderateStored XSS on Data Directory tab in JetBrains TeamCity before 2025.03.1
CVE-2025-46618 is a stored cross-site scripting (CWE-79) flaw in JetBrains TeamCity, where attacker-supplied content can be persisted and then executed when a user views the Data Directory tab. Per the CVSS vector, the attack is network-based, requires no privileges, and relies on user interaction (UI:R), meaning a victim must load the affected tab for the injected script to run. Because the scope is changed (S:C), the script executes in the victim's browser session within TeamCity, yielding limited confidentiality and integrity impact (CVSS 6.1, medium), such as acting or reading data with the victim's privileges while the tab is viewed. Any TeamCity deployment running a version before 2025.03.1 is affected, and the fix is included in 2025.03.1. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the EPSS score of 61.7% (99th percentile) indicates a high probability of exploitation within the next 30 days.
What to do: Upgrade TeamCity to 2025.03.1 or later as soon as possible and prioritize this given the elevated EPSS score. Until patched, restrict access to the administration area and Data Directory tab to trusted users and check the data directory for unexpected or suspicious uploaded content. Monitor TeamCity logs and JetBrains advisories for signs of exploitation.
| JetBrains TeamCity | All versions before 2025.03.1 (fixed in 2025.03.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
- Vendors
- jetbrains
- Products
- teamcity
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.