Impact
JetBrains TeamCity exposes a stored cross‑site scripting flaw (CWE‑79) that permits an attacker to register a build agent without authentication, embedding malicious script content into the agent’s metadata. This data is persisted and subsequently rendered by the Web interface when authorized users view agent information. Based on the nature of stored XSS, the injected script would execute in the browser context of those users, potentially enabling unauthorized actions or information disclosure.
Affected Systems
Any JetBrains TeamCity installation running a version earlier than 2026.1.2 is affected. No fixes exist for earlier versions except by upgrading to 2026.1.2 or newer.
Risk and Exploitability
The flaw carries a CVSS score of 8.1. The EPSS score is < 1 %, indicating a low likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. An unauthenticated request to the agent‑registration API, where the attacker supplies crafted metadata containing script tags. Exploitation requires the vulnerable system to accept the registration and a legitimate user to subsequently view the stored metadata.
OpenCVE Enrichment