Improper Authorization in Handler for Custom URL Scheme
CVE-2025-67739
Summary
In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure
- HIGH
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- LOW
- NONE
CWE-939 - Improper Authorization in Handler for Custom URL Scheme
The software uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.
References
Advisory Timeline
- Published