CVE-2025-67739Low· 3.1▾ SunlitIn JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
teamcity < 2025.11.2Upgrade past the affected range:
teamcity 2025.11.2Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67742Low· 3.8In JetBrains TeamCity before 2025.11 path traversal was possible via file upload
CVE-2025-67740Low· 2.7In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata
CVE-2025-67741Medium· 4.6In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
CVE-2026-106218High· 8.8In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
CVE-2026-106219Medium· 6.5In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
CVE-2022-37009Low· 3.9In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible