In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
CVSS 9.8
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server
CVSS 6.5
In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
CVSS 8.8
JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. Action : Apply mitigations in accordance with vendor i…