Impact
In JetBrains TeamCity, versions prior to 2026.1.2 and 2025.11.6, a flaw permits arbitrary code execution through the handling of Git VCS roots. The vulnerability allows an attacker to run any command on the TeamCity server by influencing the processing of Git repositories, effectively compromising the entire host. This command injection weakness, identified as CWE‑94, can undermine confidentiality, integrity, and availability. The likely attack vector is that an attacker submits a malicious Git repository or manipulates the VCS root configuration accessed over the network, although the exact exploitation steps are not detailed in the advisory.
Affected Systems
JetBrains TeamCity servers running versions earlier than 2026.1.2 or 2025.11.6 are affected. Any installation that permits configuration of Git VCS roots falls under the scope of this vulnerability.
Risk and Exploitability
The CVSS score of 9.1 classifies the issue as critical, while the EPSS score of less than 1% indicates a very low observed exploitation probability at the time of analysis. The vulnerability is not yet listed in CISA's KEV catalog. Even with the low exploitation likelihood, the potential for remote code execution and the requirement for network access to the TeamCity administration interface or exposed Git endpoints make this a high‑risk scenario that warrants immediate attention.
OpenCVE Enrichment