VulnSea

teamcity vulnerabilities

CVEs whose affected-version data names the teamcity package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-106218High· 8.8
yesterday

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible

▾ TwilightJetBrains · TeamCityvia NVD
CVE-2026-106219Medium· 6.5
yesterday

In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server

In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server

▾ SunlitJetBrains · TeamCityvia NVD
CVE-2026-100254High· 8.8
1w ago

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings

▾ Twilightjetbrains · teamcityEPSS 0.46%via NVD
CVE-2026-100253High· 8.8
1w ago

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL

▾ Twilightjetbrains · teamcityEPSS 0.43%via NVD
CVE-2026-100255High· 8.1
1w ago

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 administrator account takeover was possible via password reset

▾ Twilightjetbrains · teamcityEPSS 0.35%via NVD
CVE-2026-63077Critical· 9.8CISA KEVPoC
2mo ago

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

▾ HadalJetBrains · TeamCityEPSS 90%via CVEORG
CVE-2025-67742Low· 3.8
10mo ago

In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

▾ Sunlitjetbrains · teamcityEPSS 0.80%via NVD
CVE-2025-67741Medium· 4.6
10mo ago

In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute

In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute

▾ Sunlitjetbrains · teamcityEPSS 0.49%via NVD
CVE-2025-67740Low· 2.7
10mo ago

In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

▾ Sunlitjetbrains · teamcityEPSS 0.22%via NVD
CVE-2025-67739Low· 3.1
10mo ago

In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

▾ Sunlitjetbrains · teamcityEPSS 0.17%via NVD
teamcity vulnerabilities (CVEs) · VulnSea