CVE-2025-59457
JetBrains TeamCity vulnerability analysis and mitigation

Overview

CVE-2025-59457 is a credential leakage vulnerability in JetBrains TeamCity caused by missing Git URL validation on Windows systems. It affects all TeamCity versions before 2025.07.2 and was published on September 17, 2025, with initial analysis completed by NIST on September 22, 2025. The vulnerability carries a CVSS v3.1 base score of 7.7 (High), assigned by JetBrains (JetBrains Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-183 (Permissive List of Allowed Inputs), meaning TeamCity fails to adequately validate Git repository URLs before processing them. On Windows, this insufficient validation can be exploited by a low-privileged authenticated attacker to cause the server to leak credentials — likely by crafting a malicious Git URL that redirects authentication to an attacker-controlled host. The attack is network-based, requires no user interaction, and has a changed scope, indicating the impact extends beyond the vulnerable component itself. Related attack patterns include double encoding (CAPEC-120), Unicode encoding bypass (CAPEC-71), and exploiting multiple input interpretation layers (CAPEC-43) (JetBrains Advisory, Red Hat CVE).

Impact

Successful exploitation allows a low-privileged attacker to exfiltrate sensitive credentials stored or used by the TeamCity server on Windows, with high confidentiality impact and no integrity or availability impact. Leaked credentials could include VCS (version control system) authentication tokens, SSH keys, or service account passwords configured in TeamCity build configurations, potentially enabling lateral movement into source code repositories or other connected systems. The changed scope in the CVSS vector indicates that the credential exposure can affect systems beyond the TeamCity instance itself (JetBrains Advisory, Red Hat CVE).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.002%, reflecting a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 385231) (Red Hat CVE, Qualys Notifications).

Exploitation steps

  1. Reconnaissance: Identify TeamCity instances running on Windows with versions prior to 2025.07.2 using network scanning or Shodan/Censys queries targeting TeamCity login pages or API endpoints.
  2. Obtain low-privilege access: Authenticate to the TeamCity instance using any valid low-privilege user account (e.g., a developer or guest account).
  3. Craft malicious Git URL: Create a VCS root or build configuration that references a Git repository URL pointing to an attacker-controlled server (e.g., http://attacker.com/repo.git or using UNC paths like \\attacker.com\share) designed to capture NTLM or HTTP Basic authentication credentials.
  4. Trigger credential leakage: Initiate a build or VCS polling operation that causes TeamCity to connect to the malicious Git URL, transmitting credentials (e.g., NTLM hashes, plaintext passwords, or tokens) to the attacker's server.
  5. Capture and abuse credentials: Collect the leaked credentials on the attacker-controlled server and use them to access legitimate source code repositories or other internal systems.

Indicators of compromise

  • Network: Outbound HTTP/HTTPS or SMB connections from the TeamCity Windows server to unexpected or external IP addresses during VCS polling or build operations; NTLM authentication attempts to external hosts.
  • Logs: TeamCity server logs showing VCS root connections to unusual or external Git URLs; failed or unexpected authentication events in Windows Security Event Logs (Event ID 4648, 4624) involving the TeamCity service account.
  • Configuration: Newly created or modified VCS roots in TeamCity pointing to external or unrecognized Git repository URLs; build configurations referencing URLs not matching approved repository lists.

Mitigation and workarounds

JetBrains has released TeamCity version 2025.07.2, which addresses this vulnerability by implementing proper Git URL validation. Organizations should upgrade to version 2025.07.2 or later as the primary remediation. As interim measures, administrators should audit all VCS root configurations for suspicious Git URLs, restrict TeamCity's outbound network access to approved repository hosts, and rotate any credentials that may have been exposed. Monitoring for unexpected outbound connections from the TeamCity server is also recommended (JetBrains Advisory).

Additional resources


SourceThis report was generated using AI

Related JetBrains TeamCity vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65906CRITICAL10
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 23, 2026
CVE-2026-63077CRITICAL9.8
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
YesYesJul 27, 2026
CVE-2026-59796HIGH8.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59795MEDIUM6.1
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026
CVE-2026-59794MEDIUM5.4
  • JetBrains TeamCity logoJetBrains TeamCity
  • cpe:2.3:a:jetbrains:teamcity
NoYesJul 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management