2026.1.4,
2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.jetbrains.com/privacy-security/issues-fixed/ |
|
Wed, 30 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | TeamCity Sandbox Escape via Kotlin DSL Settings Enables Code Execution |
Wed, 30 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL | |
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: JetBrains
Published:
Updated: 2026-09-30T15:48:41.673Z
Reserved: 2026-09-25T17:02:01.996Z
Link: CVE-2026-100253
No data.
Status : Awaiting Analysis
Published: 2026-09-30T16:16:55.780
Modified: 2026-09-30T16:44:39.840
Link: CVE-2026-100253
No data.
OpenCVE Enrichment
Updated: 2026-09-30T17:00:16Z