Executive brief
JetBrains TeamCity, a platform used by software teams to automate building and testing code, contained a vulnerability that allowed users to bypass security restrictions. An attacker with basic access could escape the restricted environment used for configuration scripts to run unauthorized code on the server. This could lead to a full takeover of the build system, potentially exposing sensitive source code or allowing the injection of malicious code into software releases.
Technical details
A code injection vulnerability (CWE-94) exists in JetBrains TeamCity due to an improper sandbox implementation for Kotlin DSL (Domain Specific Language) configurations. An authenticated attacker with permissions to modify project configurations can craft a malicious Kotlin DSL script that escapes the intended execution sandbox. This allows for arbitrary code execution on the TeamCity server with the privileges of the service account. The vulnerability is fixed in versions 2026.1.2 and 2025.11.6.
Affected products
- JetBrains TeamCity before 2026.1.2, 2025.11.6
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory