CVE-2025-26493: XSS
Published Feb 11, 2025
·Updated
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab
Affected Software
2 affected components
JetBrains TeamCity<2024.12.2
JetBrains TeamCity<2024.12.2
Event History
Feb 11, 2025
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-26493?
CVE-2025-26493 has been classified with a moderate severity rating due to the potential for DOM-based XSS attacks.
2
How do I fix CVE-2025-26493?
To fix CVE-2025-26493, upgrade JetBrains TeamCity to version 2024.12.2 or later.
3
What are the exploit characteristics of CVE-2025-26493?
CVE-2025-26493 allows attackers to execute scripts in the context of the user’s browser through vulnerable components in the Code Inspection Report tab.
4
Can CVE-2025-26493 lead to data exposure?
Yes, exploiting CVE-2025-26493 could allow attackers to access sensitive user information through script execution.
5
What specific versions of JetBrains TeamCity are affected by CVE-2025-26493?
JetBrains TeamCity versions prior to 2024.12.2 are affected by CVE-2025-26493.