Impact
A reflected XSS flaw exists on TeamCity’s repository download page, allowing an attacker to inject and execute arbitrary scripts in the victim’s browser, potentially exposing session data or performing unauthorized actions. This weakness is identified as CWE-79.
Affected Systems
JetBrains TeamCity versions earlier than 2026.1, including 2025.11.5, are affected by the reflected XSS vulnerability on the repository download page.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while EPSS data is not available and the vulnerability is not in the CISA KEV catalog. The likely attack vector involves an attacker supplying a malicious URL or query string to a victim who then visits the repository download page, at which point the injected script would run. Because reflected XSS can be triggered with a simple crafted link, the exploitability is straightforward for an attacker who can target users with such links.
OpenCVE Enrichment