JetBrains TeamCity Cross-Site Request Forgery Vulnerability in GitHub App Connection Flow

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in JetBrains TeamCity versions prior to 2025.07. This vulnerability occurs during the GitHub App connection process, allowing an attacker to potentially manipulate the connection flow.

Impact

Exploitation of this vulnerability could lead to unauthorized actions being performed on behalf of the user, within the context of the GitHub App integration.

Remediation

Users can upgrade to JetBrains TeamCity version 2025.07 or later to address this vulnerability.

Added: Jul 28, 2025, 5:46 PM
Updated: Jul 28, 2025, 5:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.