Vulnerability record · CVE-2025-46618 · published 25 April 2025
CVE-2025-46618: JetBrains TeamCity stored XSS on Data Directory tab
Jetbrains · Teamcity
JetBrains TeamCity before 2025.03.1 is affected by a stored cross-site scripting flaw on the Data Directory tab. Because the payload is stored server-side, it can be served to other users of the instance, making it a persistent risk in a product that is a common target for supply-chain style attacks.
Description
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (6.1) with user interaction required, but the high EPSS percentile and TeamCity's history as a targeted product warrant prompt patching.
What it is
JetBrains TeamCity before 2025.03.1 is affected by a stored cross-site scripting flaw on the Data Directory tab. Because the payload is stored server-side, it can be served to other users of the instance, making it a persistent risk in a product that is a common target for supply-chain style attacks.
Impact
An attacker can execute script in the browser context of a victim who views the affected tab, potentially stealing session data or performing actions as that user. The CVSS scope change (S:C) indicates impact can extend beyond the vulnerable component.
Attack surface
Reachable over the network via the TeamCity web interface; the vector shows no privileges required (PR:N) but user interaction is required (UI:R) for the victim to trigger the stored payload.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high at roughly 0.617 (99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Upgrade TeamCity to 2025.03.1 or later, which is the fixed version per the vendor advisory.
- If immediate upgrade is not possible, restrict access to the TeamCity web interface to trusted networks and users.
- Review and sanitize any user-supplied content rendered on the Data Directory tab.
- Monitor the vendor advisory page for further guidance and any updated fixed versions.
Detection
- Search TeamCity logs and stored content for script tags or event handler attributes associated with the Data Directory tab.
- Monitor for anomalous authenticated sessions or actions originating from users who recently viewed the Data Directory tab.
- Alert on unexpected outbound requests or script loads from TeamCity pages.
- Review web access logs for suspicious payloads submitted to endpoints backing the Data Directory tab.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ | Vendor Advisory |
Track CVE-2025-46618 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-46618), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.