Impact
JetBrains TeamCity versions before 2026.1.2 and 2025.11.6 contain a Kotlin DSL sandbox escape that permits an attacker to execute arbitrary Kotlin code. The vulnerability is a code injection flaw (CWE‑94), providing the attacker with full compromise of confidentiality, integrity, and availability for the affected system. By crafting a malicious DSL script, an attacker can run any code with the permissions of the TeamCity server process.
Affected Systems
The vulnerable products are JetBrains TeamCity, affected by versions earlier than 2026.1.2 and 2025.11.6. Any installation of these releases that accepts external Kotlin DSL scripts is susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk, while the EPSS score of less than 1% suggests that, as of now, exploitation incidence is low. The vulnerability is not yet listed in the CISA KEV catalog. The attack vector is presumably remote, as it can be triggered when an attacker can upload or modify a Kotlin DSL script in a project, thereby escaping the sandbox and executing arbitrary code on the TeamCity host.
OpenCVE Enrichment