
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68162 is a vulnerability in JetBrains TeamCity where the Maven embedder component allows loading extensions via project configuration, potentially enabling unauthorized functionality inclusion. It affects all TeamCity versions before 2025.11 and was published on December 16, 2025. The vulnerability carries a CVSS v3.1 base score of 2.7 (Low), requiring high-privilege network access with no user interaction (JetBrains, Red Hat CVE).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), where TeamCity's embedded Maven component fails to restrict the loading of extensions defined within project configuration files. An authenticated, high-privileged attacker can craft a malicious project configuration that instructs the Maven embedder to load unauthorized or attacker-controlled extensions during build execution. Exploitation requires network access and high-privilege credentials, limiting the practical attack surface significantly (JetBrains, Red Hat CVE).
Successful exploitation could allow a high-privileged attacker to inject unauthorized Maven extensions into the TeamCity build environment, resulting in limited integrity compromise. The vulnerability has no impact on confidentiality or availability, and its scope is unchanged, meaning it cannot be leveraged to directly affect systems beyond the TeamCity instance itself. The practical risk is constrained by the requirement for pre-existing high-privilege access (JetBrains).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed. The EPSS score is extremely low at 0.00001, reflecting minimal likelihood of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, and no threat actor attribution has been reported (Red Hat CVE).
JetBrains has addressed this vulnerability in TeamCity version 2025.11 and later; upgrading to this release is the recommended remediation. As interim measures, organizations should restrict high-privilege access to TeamCity instances, enforce strict review of project configurations, and audit any Maven-related build step configurations for unexpected extension references. Implementing least-privilege access controls for configuration modifications will further reduce exposure (JetBrains).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."