CVE-2025-52876
largeReflected XSS in JetBrains TeamCity favoriteIcon page (fixed in 2025.03.3)
CVE-2025-52876 is a reflected cross-site scripting flaw (CWE-79) in the favoriteIcon page of JetBrains TeamCity, the vendor's self-hosted CI/CD server, fixed in TeamCity 2025.03.3. To trigger it, an attacker crafts a malicious link to the affected favoriteIcon endpoint and persuades an authenticated TeamCity user to open it, since the CVSS vector (PR:L/UI:R) indicates a low-privileged account and user interaction are required. If the victim clicks the link, attacker-controlled script runs in their browser session with limited confidentiality and integrity impact and no availability loss, and the changed scope means the script can affect components outside the vulnerable page. All TeamCity deployments running versions before 2025.03.3 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the 22.6% EPSS score (98th percentile) suggests a high likelihood of exploitation attempts within 30 days.
What to do: Upgrade JetBrains TeamCity to 2025.03.3 or later. Until patching is complete, reduce exposure by placing internet-facing TeamCity servers behind a VPN or allowlist and caution users against opening untrusted links pointing at the server. Prioritize patching publicly accessible instances, as exposed TeamCity servers are a frequent target for follow-on attacks.
| jetbrains teamcity | all versions before 2025.03.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible
- Vendors
- jetbrains
- Products
- teamcity
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.