ZeroHour

CVE-2025-52876

large

Reflected XSS in JetBrains TeamCity favoriteIcon page (fixed in 2025.03.3)

CVSS 3.1
5.4 medium
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2025-52876 is a reflected cross-site scripting flaw (CWE-79) in the favoriteIcon page of JetBrains TeamCity, the vendor's self-hosted CI/CD server, fixed in TeamCity 2025.03.3. To trigger it, an attacker crafts a malicious link to the affected favoriteIcon endpoint and persuades an authenticated TeamCity user to open it, since the CVSS vector (PR:L/UI:R) indicates a low-privileged account and user interaction are required. If the victim clicks the link, attacker-controlled script runs in their browser session with limited confidentiality and integrity impact and no availability loss, and the changed scope means the script can affect components outside the vulnerable page. All TeamCity deployments running versions before 2025.03.3 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the 22.6% EPSS score (98th percentile) suggests a high likelihood of exploitation attempts within 30 days.

What to do: Upgrade JetBrains TeamCity to 2025.03.3 or later. Until patching is complete, reduce exposure by placing internet-facing TeamCity servers behind a VPN or allowlist and caution users against opening untrusted links pointing at the server. Prioritize patching publicly accessible instances, as exposed TeamCity servers are a frequent target for follow-on attacks.

Affected
jetbrains teamcityall versions before 2025.03.3
Estimated exposure
largeon the order of tens of thousands of TeamCity servers, many internet-exposed (public scans commonly show roughly 10k-50k reachable instances) — TeamCity is a widely deployed CI/CD server and public internet scans (e.g., Shodan/Censys) routinely index tens of thousands of reachable TeamCity instances, though the total count including internal-only servers is unknown.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains TeamCity before 2025.03.3 reflected XSS on the favoriteIcon page was possible

Vendors
jetbrains
Products
teamcity
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.