CVE-2025-68165: XSS
Published Dec 16, 2025
·Updated
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
Affected Software
1 affected component
JetBrains TeamCity<2025.11
Event History
Dec 16, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68165?
CVE-2025-68165 has a moderate severity level due to the reflected XSS vulnerability it introduces.
2
How do I fix CVE-2025-68165?
To fix CVE-2025-68165, upgrade your JetBrains TeamCity to version 2025.11 or later.
3
What type of vulnerability is CVE-2025-68165?
CVE-2025-68165 is a reflected cross-site scripting (XSS) vulnerability.
4
Can CVE-2025-68165 be exploited remotely?
Yes, CVE-2025-68165 can be exploited remotely through manipulated VCS Root setup.
5
What impact does CVE-2025-68165 have on security?
CVE-2025-68165 could allow attackers to inject malicious scripts, compromising user data and session integrity.