JetBrains Hub Race Condition Vulnerability Allowing User Limit Bypass via Invitations

Vulnerability

A race condition vulnerability has been identified in JetBrains Hub versions prior to 2025.3.104992. This vulnerability allows users to bypass the invitation-based user limit by exploiting the timing of certain operations. As a result, it could lead to unauthorized user additions or privileges.

Impact

Exploitation of this vulnerability could result in unauthorized users being added or granted privileges, potentially leading to misuse of access rights or disruption of services.

Remediation

Users can update to JetBrains Hub version 2025.3.104992 or later to address this vulnerability.

Added: Nov 10, 2025, 2:35 PM
Updated: Nov 10, 2025, 3:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.8
impact
0.6
exploitability
6.2
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.