CVE-2025-31140
CVSS 3.1 Score 4.6 of 10 (medium)
Details
Summary
CVE-2025-31140 is a newly disclosed vulnerability affecting JetBrains TeamCity versions prior to 2025.03. This issue allows Cross-Site Scripting (XSS) attacks on the Cloud Profiles page, potentially enabling malicious actors to inject malicious code into a user's browser and steal sensitive information. An attacker could exploit this vulnerability by tricking a TeamCity user into visiting a specially crafted webpage. The successful exploitation of this XSS vulnerability could lead to unauthorized access, data theft, or other malicious activities. Users are advised to update their TeamCity installations to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- TeamCity
Affected Vendors
- JetBrains