Relative Path Traversal in TeamCity - CVE-2025-59456
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote user to access files outside the intended upload directory.
The vulnerability exists due to path traversal in project archive upload when processing uploaded project archives. A remote user can upload a specially crafted archive containing traversal sequences to access files outside the intended upload directory.