CVE-2025-64457Medium· 4.2▾ SunlitIn JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.09%
In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition
dottrace < 2025.2.5resharper < 2025.2.5rider < 2025.2.5Upgrade past the affected range:
dottrace 2025.2.5resharper 2025.2.5rider 2025.2.5Connected by shared product, vendor, weakness, or advisory.
CVE-2025-58335Medium· 5.5In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.284.50, 243.284.54, 243.284.50 information disclosure was possible via search_project function
CVE-2025-58334High· 8.1In JetBrains IDE Services before 2025.5.0.1086, 2025.4.2.2164 users without appropriate permissions could assign high-privileged role for themselves
CVE-2026-63077Critical· 9.8In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
CVE-2026-75050High· 7.1In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters
CVE-2026-75049Medium· 6.5In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creation endpoint
CVE-2026-75048High· 8.2In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible