← Vulnerability feed

Vulnerability record · CVE-2025-46618 · published 25 April 2025

CVE-2025-46618: JetBrains TeamCity stored XSS on Data Directory tab

Jetbrains · Teamcity

JetBrains TeamCity before 2025.03.1 is affected by a stored cross-site scripting flaw on the Data Directory tab. Because the payload is stored server-side, it can be served to other users of the instance, making it a persistent risk in a product that is a common target for supply-chain style attacks.

6.1 CVSS 3.1 Medium EPSS 63% · top 0.8% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS rates it medium (6.1) with user interaction required, but the high EPSS percentile and TeamCity's history as a targeted product warrant prompt patching.

What it is

JetBrains TeamCity before 2025.03.1 is affected by a stored cross-site scripting flaw on the Data Directory tab. Because the payload is stored server-side, it can be served to other users of the instance, making it a persistent risk in a product that is a common target for supply-chain style attacks.

Impact

An attacker can execute script in the browser context of a victim who views the affected tab, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.

Attack surface

Reachable over the network via the TeamCity web interface; the vector shows no privileges required (PR:N) but user interaction is required (UI:R) for the victim to trigger the stored payload.

Exploitation

Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.617 (99th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Upgrade TeamCity to 2025.03.1 or later, which is the fixed version per the vendor advisory.
  • If immediate upgrade is not possible, restrict access to the TeamCity web interface to trusted networks and users.
  • Review and sanitize any user-supplied content rendered on the Data Directory tab.
  • Monitor the vendor advisory page for further guidance and any updated fixed versions.

Detection

  • Search TeamCity logs and stored content for script tags or event handler attributes associated with the Data Directory tab.
  • Monitor for anomalous authenticated sessions or actions originating from users who recently viewed the Data Directory tab.
  • Alert on unexpected outbound requests or script loads from TeamCity pages.
  • Review web access logs for suspicious payloads submitted to endpoints backing the Data Directory tab.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-46618 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2024-27198JetBrains TeamCity authentication bypass allows admin actionsJetBrains TeamCity before 2023.11.4 contains an authentication bypass via an alternate path (CWE-288), letting an unauthenticated attacker reach func…KEVEPSS 100%analysed9.8CVE-2023-42793JetBrains TeamCity authentication bypass leads to remote code executionJetBrains TeamCity before 2023.05.4 contains an authentication bypass via an alternate path, classified as CWE-288 and CWE-306, that allows an unauth…KEVEPSS 100%analysed7.3CVE-2024-27199JetBrains TeamCity path traversal enables limited admin actionsJetBrains TeamCity before 2023.11.4 is vulnerable to relative path traversal that lets an unauthenticated remote party perform limited administrative…KEVEPSS 100%analysed10.0CVE-2026-65906Jetbrains teamcity code injection vulnerabilityIn JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possibleEPSS 0.66%9.8CVE-2025-54530Jetbrains teamcity incorrect default permissions vulnerabilityIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.18%9.8CVE-2025-46433Jetbrains teamcity relative path traversal vulnerabilityIn JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possibleEPSS 0.55%9.8CVE-2024-41827Jetbrains teamcity insufficient session expiration vulnerabilityIn JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expirationEPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2025-46618), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.