JetBrains TeamCity Improper Access Control Vulnerability Exposing GitHub App Token Metadata

Vulnerability

A vulnerability exists in JetBrains TeamCity versions prior to 2025.11 that involves improper access control, which could lead to the unintentional exposure of metadata related to GitHub App tokens.

Impact

This vulnerability could result in unauthorized access to sensitive metadata associated with GitHub App tokens, potentially leading to further security implications depending on the nature of the exposed information.

Remediation

Users can update to JetBrains TeamCity version 2025.11 or later to address this vulnerability.

Added: Dec 11, 2025, 4:20 PM
Updated: Dec 11, 2025, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
4.8
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.