Skip to main content

Improper Authorization in Handler for Custom URL Scheme

CVE-2025-67739

Severity Low
Score 3.1/10

Summary

In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • LOW
  • NONE

CWE-939 - Improper Authorization in Handler for Custom URL Scheme

The software uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.

References

Advisory Timeline

  • Published