JetBrains TeamCity Path Traversal Vulnerability via Plugin Unpacking on Windows

Vulnerability

A path traversal vulnerability has been identified in JetBrains TeamCity versions prior to 2025.07. This vulnerability allows for unauthorized file access through plugin unpacking on Windows systems.

Impact

Exploitation of this vulnerability could lead to unauthorized access to files on the server.

Remediation

Users can upgrade to TeamCity version 2025.07 or later to address this vulnerability.

Added: Jul 28, 2025, 5:38 PM
Updated: Jul 28, 2025, 5:38 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
3.3
exploitability
4.8
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.