JetBrains TeamCity Path Traversal Vulnerability in Project Archive Upload

Vulnerability

A path traversal vulnerability has been identified in JetBrains TeamCity versions prior to 2025.07.2. This vulnerability allows attackers to manipulate file paths during the project archive upload process, potentially leading to unauthorized access or modification of files on the server.

Impact

Exploitation of this vulnerability could lead to unauthorized file access or modification on the server where TeamCity is running.

Remediation

Users can upgrade to JetBrains TeamCity version 2025.07.2 or later to address this vulnerability.

Added: Sep 17, 2025, 9:21 AM
Updated: Sep 17, 2025, 2:45 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
3.3
exploitability
4.8
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.