CVE-2025-52877
largeReflected XSS in JetBrains TeamCity diskUsageBuildsStats Admin Page
CVE-2025-52877 is a reflected cross-site scripting (CWE-79) flaw in JetBrains TeamCity, occurring on the diskUsageBuildsStats page. An attacker must craft a malicious link to that page and persuade an authenticated user to open it; the CVSS vector (PR:H, UI:R) indicates the victim needs administrator-level privileges, and the changed scope (S:C) means injected script can affect other pages or components beyond the vulnerable one. Successful exploitation lets the attacker execute actions in the victim's session with low-to-moderate confidentiality and integrity impact, such as reading or altering TeamCity administration data, and could be a foothold for pivoting into CI/CD pipelines. All TeamCity Server installations running a version before 2025.03.3 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but the EPSS score of 22% (98th percentile) indicates a relatively high likelihood of exploitation within the next 30 days.
What to do: Upgrade TeamCity to version 2025.03.3 or later. As an interim mitigation, avoid clicking untrusted links to the TeamCity admin UI while logged in as an administrator, and review web/access logs for suspicious or unexpected requests targeting the diskUsageBuildsStats page. Because TeamCity servers often hold build secrets and deployment credentials, treat any signs of exploitation as potential CI/CD compromise and rotate exposed tokens if needed.
| JetBrains TeamCity | all versions before 2025.03.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In JetBrains TeamCity before 2025.03.3 reflected XSS on diskUsageBuildsStats page was possible
- Vendors
- jetbrains
- Products
- teamcity
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.