
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68166 is a DOM-based Cross-Site Scripting (XSS) vulnerability in JetBrains TeamCity affecting the OAuth connections tab. It impacts all TeamCity versions prior to 2025.11 and was published on December 16, 2025. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, JetBrains Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the DOM-based variant (CAPEC-588). The flaw exists in the OAuth connections tab of the TeamCity web interface, where attacker-controlled input is processed by client-side JavaScript and written to the DOM without adequate sanitization or encoding. Exploitation requires no authentication but does require user interaction — a victim must visit or be directed to a maliciously crafted page or URL that triggers the DOM manipulation (Red Hat Advisory, JetBrains Advisory).
Successful exploitation allows an attacker to inject and execute arbitrary JavaScript in the context of a victim's browser session on the TeamCity instance. This can lead to theft of session tokens and credentials — particularly dangerous if the victim is a TeamCity administrator — as well as unauthorized actions performed on behalf of the victim, such as modifying CI/CD pipeline configurations. Confidentiality and integrity are both impacted at a low level, while availability is not directly affected (Red Hat Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.158%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 279408) and Qualys (detection ID 530766) (Tenable Nessus, Red Hat Advisory).
JetBrains has released a fix in TeamCity version 2025.11; upgrading to this version or later is the primary recommended remediation (JetBrains Advisory). As interim mitigations, administrators should restrict access to the TeamCity OAuth connections tab to trusted users only, deploy a Web Application Firewall (WAF) configured to detect and block XSS payloads, and monitor for suspicious activity or unexpected script executions. Users should also ensure browser security controls (e.g., Content Security Policy headers) are enforced where possible.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."