#VU113421 Path traversal in TeamCity - CVE-2025-54531
Published: July 29, 2025
TeamCity
JetBrains s.r.o.
Description
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences during plugin unpacking on Windows. A remote attacker can trick the victim into unpacking a specially crafted package and overwrite arbitrary files on the system.