Executive brief
JetBrains TeamCity, a platform used by software teams to automate building and testing code, contains a vulnerability that could expose sensitive information. An authenticated user could potentially view configuration details or environment variables that should remain private. This exposure could lead to the leak of internal system details, though it does not directly allow for system takeover or data destruction.
Technical details
JetBrains TeamCity versions prior to 2025.11.2 are vulnerable to the exposure of sensitive information through environmental variables (CWE-526). The flaw exists in how default agent parameters are handled, potentially leaking sensitive configuration data to authenticated users. An attacker with low-privileged network access can exploit this to gain insight into the build environment without requiring user interaction. The issue is addressed in version 2025.11.2.
Affected products
- JetBrains TeamCity before 2025.11.2
Timeline
- 2026-05-29: advisory: CVE-2026-49377 published by JetBrains
- 2026-05-29: patched: Fixed in version 2025.11.2