JetBrains TeamCity Password Exposure Vulnerability via Command Line in Mercurial Pull Operations

Vulnerability

A vulnerability allowing password exposure was identified in JetBrains TeamCity versions prior to 2025.07. This issue arises when passwords are included in the command line during 'hg pull' operations, potentially leading to unauthorized disclosure of sensitive information.

Impact

Exploitation of this vulnerability could result in the unintended exposure of user passwords, creating a risk of unauthorized access to accounts or resources.

Remediation

Users can upgrade to JetBrains TeamCity version 2025.07 or later to address this vulnerability.

Added: Jul 28, 2025, 5:19 PM
Updated: Jul 28, 2025, 5:19 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.