CVE-2025-67741: XSS
Published Dec 11, 2025
·Updated
In JetBrains TeamCity before 2025.11 stored XSS was possible via session attribute
Affected Software
2 affected components
JetBrains TeamCity<2025.11
JetBrains TeamCity<2025.11
Event History
Dec 11, 2025
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67741?
CVE-2025-67741 has a high severity rating due to the potential for stored XSS attacks that could compromise user sessions.
2
How do I fix CVE-2025-67741?
To fix CVE-2025-67741, upgrade your JetBrains TeamCity installation to version 2025.11 or later.
3
What type of vulnerability is CVE-2025-67741?
CVE-2025-67741 is a stored cross-site scripting (XSS) vulnerability.
4
What impact does CVE-2025-67741 have on JetBrains TeamCity users?
CVE-2025-67741 can lead to unauthorized access and the execution of malicious scripts in the context of user sessions.
5
Are there any known exploits for CVE-2025-67741?
As of now, there are no publicly known exploits for CVE-2025-67741, but it remains a serious concern for affected users.