CVE-2025-46618: XSS
Published Apr 25, 2025
·Updated
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab
Affected Software
2 affected components
JetBrains TeamCity<2025.03.1
JetBrains TeamCity<2025.03.1
Event History
Apr 25, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Oct 7, 57345
Event
via FIRST·11:20 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-46618?
CVE-2025-46618 is categorized as a stored cross-site scripting (XSS) vulnerability, which can pose significant security risks to affected users.
2
How do I fix CVE-2025-46618?
To fix CVE-2025-46618, upgrade your JetBrains TeamCity installation to version 2025.03.1 or later.
3
What versions of JetBrains TeamCity are affected by CVE-2025-46618?
All versions of JetBrains TeamCity prior to 2025.03.1 are vulnerable to CVE-2025-46618.
4
What kind of attack is possible due to CVE-2025-46618?
CVE-2025-46618 allows attackers to execute malicious scripts in the context of the user’s browser through stored XSS.
5
Where can I find more information about CVE-2025-46618?
For detailed information about CVE-2025-46618, refer to the JetBrains security updates page.