CVE-2025-68166: XSS
Published Dec 16, 2025
·Updated
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Affected Software
1 affected component
JetBrains TeamCity<2025.11
Event History
Dec 16, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-68166?
CVE-2025-68166 is rated as a medium severity vulnerability due to its potential for exploitation via DOM-based XSS.
2
How do I fix CVE-2025-68166?
To fix CVE-2025-68166, update JetBrains TeamCity to version 2025.11 or later.
3
What is the exploit type of CVE-2025-68166?
CVE-2025-68166 is classified as a DOM-based Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2025-68166?
CVE-2025-68166 affects users of JetBrains TeamCity versions prior to 2025.11.
5
What components are involved in CVE-2025-68166?
CVE-2025-68166 specifically involves the OAuth connections tab in JetBrains TeamCity.