| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol |
| In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible |
| In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration |
| In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible |
| In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks |
| In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data |
| In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible |
| In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
| In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
| In JetBrains TeamCity before 2026.1,
2025.11.5 reflected XSS was possible on the repository download page |
| In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin |
| In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters |
| In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion |
| In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names |
| In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible |
| In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible |
| In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible |
| In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible |
| In JetBrains TeamCity before 2026.1
2025.11.5 authenticated users could expose server API to unauthorised access |
| In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible |