Impact
JetBrains TeamCity versions prior to 2025.11.3 allow an open redirect in the React project creation flow, enabling an attacker to redirect users to arbitrary URLs. This can be exploited for phishing, drive‑by downloads, or other social‑engineering attacks. The weakness is identified as CWE‑601, indicating improper validation of redirect destinations.
Affected Systems
JetBrains TeamCity, versions before 2025.11.3
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% demonstrates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft a URL that is accepted by the project creation interface and have a user follow it, typically via a malicious link or compromised internal portal. Because it does not grant arbitrary code execution or privileged access, the impact is limited to user deception, but it remains a concern for environments where internal users routinely click on untrusted links.
OpenCVE Enrichment