Junglewise Threat Intelligence

CVE-2026-49371: JetBrains TeamCity reflected XSS in keyword filter

CVE-2026-49371 · Severity: high · CVSS 7.1 · Published 2026-05-29

Technologies: Jetbrains TeamCity. Vendors: Jetbrains.

Executive brief

JetBrains TeamCity, a platform used by software teams to automate building and testing code, is affected by a security flaw in its search filtering system. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of the user within the TeamCity environment.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in JetBrains TeamCity before version 2026.1.1. The flaw is located in the keyword filter component, where user-supplied input is improperly neutralized before being rendered in the web interface (CWE-79). An unauthenticated remote attacker can exploit this by inducing a user to visit a specially crafted URL. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or sensitive data disclosure. The issue is resolved in TeamCity version 2026.1.1.

Affected products

  • JetBrains TeamCity before 2026.1.1

Timeline

  • 2026-05-29: advisory: CVE-2026-49371 published by JetBrains
  • 2026-05-29: patched: Fixed in version 2026.1.1

References

Related threats