CVE-2025-68268: XSS
Published Dec 16, 2025
·Updated
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
Affected Software
2 affected components
JetBrains TeamCity<2025.11.1
JetBrains TeamCity<2025.11.1
Event History
Dec 16, 2025
CVE Published
via MITRE·03:27 PM
Data Sourced
via MITRE·03:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-68268?
CVE-2025-68268 is classified as a medium severity vulnerability due to the potential for reflected XSS attacks.
2
How do I fix CVE-2025-68268?
To fix CVE-2025-68268, update JetBrains TeamCity to version 2025.11.1 or later.
3
What does CVE-2025-68268 affect?
CVE-2025-68268 affects JetBrains TeamCity versions prior to 2025.11.1.
4
What is reflected XSS in the context of CVE-2025-68268?
Reflected XSS in CVE-2025-68268 refers to the attacker being able to inject malicious scripts on the storage settings page.
5
Is CVE-2025-68268 exploitable without authentication?
Yes, CVE-2025-68268 can be exploited without authentication, allowing any user to trigger the reflected XSS.