ZeroHour

CVE-2025-52877

large

Reflected XSS in JetBrains TeamCity diskUsageBuildsStats Admin Page

CVSS 3.1
4.8 medium
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2025-52877 is a reflected cross-site scripting (CWE-79) flaw in JetBrains TeamCity, occurring on the diskUsageBuildsStats page. An attacker must craft a malicious link to that page and persuade an authenticated user to open it; the CVSS vector (PR:H, UI:R) indicates the victim needs administrator-level privileges, and the changed scope (S:C) means injected script can affect other pages or components beyond the vulnerable one. Successful exploitation lets the attacker execute actions in the victim's session with low-to-moderate confidentiality and integrity impact, such as reading or altering TeamCity administration data, and could be a foothold for pivoting into CI/CD pipelines. All TeamCity Server installations running a version before 2025.03.3 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 22% (98th percentile) indicates a relatively high likelihood of exploitation within the next 30 days.

What to do: Upgrade TeamCity to version 2025.03.3 or later. As an interim mitigation, avoid clicking untrusted links to the TeamCity admin UI while logged in as an administrator, and review web/access logs for suspicious or unexpected requests targeting the diskUsageBuildsStats page. Because TeamCity servers often hold build secrets and deployment credentials, treat any signs of exploitation as potential CI/CD compromise and rotate exposed tokens if needed.

Affected
JetBrains TeamCityall versions before 2025.03.3
Estimated exposure
largetens of thousands of TeamCity Server deployments, with roughly 10,000-30,000 instances visible to public internet scans — Public internet-wide scan data (e.g., Shodan/Censys) historically shows TeamCity servers in the tens of thousands worldwide, and self-managed TeamCity is a widely adopted CI/CD platform, so the exposed and installed base is plausibly in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible

Vendors
jetbrains
Products
teamcity
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.