JetBrains TeamCity Maven Embedder Extension Loading Vulnerability

Vulnerability

A vulnerability exists in JetBrains TeamCity versions prior to 2025.11, where the Maven embedder allowed the loading of extensions through project configuration. This could potentially be exploited to execute arbitrary code or introduce malicious behavior into the project.

Impact

Exploitation of this vulnerability could lead to unauthorized loading of extensions, potentially allowing for arbitrary code execution or manipulation of project behavior.

Remediation

Users can upgrade to TeamCity version 2025.11 or later to address this vulnerability.

Added: Dec 16, 2025, 6:53 PM
Updated: Dec 16, 2025, 6:53 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.