2026.1.4,
2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Thu, 01 Oct 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jetbrains
Jetbrains teamcity |
|
| Vendors & Products |
Jetbrains
Jetbrains teamcity |
Wed, 30 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Authenticated Command Execution via CRLF Injection in TeamCity Pipeline Git Settings |
Wed, 30 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-10-01T03:55:44.073Z
Reserved: 2026-09-25T17:02:02.459Z
Link: CVE-2026-100254
Updated: 2026-09-30T15:43:05.431Z
Status : Undergoing Analysis
Published: 2026-09-30T16:16:55.947
Modified: 2026-10-01T04:18:03.680
Link: CVE-2026-100254
No data.
OpenCVE Enrichment
Updated: 2026-10-01T00:00:11Z