JetBrains TeamCity Open Redirect Vulnerability in React Project Creation Flow

Vulnerability

A open redirect vulnerability has been identified in JetBrains TeamCity versions prior to 2025.11.3. This vulnerability occurs during the React project creation process, allowing for unauthorized redirection to external sites.

Impact

Exploitation of this vulnerability could lead to open redirect, potentially allowing for phishing attacks or other malicious activities by redirecting users to harmful sites.

Remediation

Users can update to JetBrains TeamCity version 2025.11.3 or later to address this vulnerability.

Added: Feb 25, 2026, 4:59 PM
Updated: Feb 25, 2026, 4:59 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.2
exploitability
4.2
remediation
7.7
relevance
3.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.