
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59457 is a credential leakage vulnerability in JetBrains TeamCity caused by missing Git URL validation on Windows systems. It affects all TeamCity versions before 2025.07.2 and was published on September 17, 2025, with initial analysis completed by NIST on September 22, 2025. The vulnerability carries a CVSS v3.1 base score of 7.7 (High), assigned by JetBrains (JetBrains Advisory, Red Hat CVE).
The root cause is classified as CWE-183 (Permissive List of Allowed Inputs), meaning TeamCity fails to adequately validate Git repository URLs before processing them. On Windows, this insufficient validation can be exploited by a low-privileged authenticated attacker to cause the server to leak credentials — likely by crafting a malicious Git URL that redirects authentication to an attacker-controlled host. The attack is network-based, requires no user interaction, and has a changed scope, indicating the impact extends beyond the vulnerable component itself. Related attack patterns include double encoding (CAPEC-120), Unicode encoding bypass (CAPEC-71), and exploiting multiple input interpretation layers (CAPEC-43) (JetBrains Advisory, Red Hat CVE).
Successful exploitation allows a low-privileged attacker to exfiltrate sensitive credentials stored or used by the TeamCity server on Windows, with high confidentiality impact and no integrity or availability impact. Leaked credentials could include VCS (version control system) authentication tokens, SSH keys, or service account passwords configured in TeamCity build configurations, potentially enabling lateral movement into source code repositories or other connected systems. The changed scope in the CVSS vector indicates that the credential exposure can affect systems beyond the TeamCity instance itself (JetBrains Advisory, Red Hat CVE).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.002%, reflecting a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 385231) (Red Hat CVE, Qualys Notifications).
http://attacker.com/repo.git or using UNC paths like \\attacker.com\share) designed to capture NTLM or HTTP Basic authentication credentials.JetBrains has released TeamCity version 2025.07.2, which addresses this vulnerability by implementing proper Git URL validation. Organizations should upgrade to version 2025.07.2 or later as the primary remediation. As interim measures, administrators should audit all VCS root configurations for suspicious Git URLs, restrict TeamCity's outbound network access to approved repository hosts, and rotate any credentials that may have been exposed. Monitoring for unexpected outbound connections from the TeamCity server is also recommended (JetBrains Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."