JetBrains TeamCity Path Traversal Vulnerability via File Upload

Vulnerability

A path traversal vulnerability has been identified in JetBrains TeamCity versions prior to 2025.11. The issue allows unauthorized users to manipulate file upload paths, potentially leading to unauthorized file access or modification on the server.

Impact

Exploitation of this vulnerability could result in unauthorized access to files on the server, potentially allowing for modification or disclosure of sensitive information.

Remediation

Users can update to TeamCity version 2025.11 or later to address this vulnerability.

Added: Dec 11, 2025, 4:17 PM
Updated: Dec 11, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
2.5
exploitability
4.8
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.