Sceawere

Vulnerability Detail

CVE-2026-106219UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

TeamCity Git Submodule Path Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
8h ago
Vendor
JetBrains
Product
TeamCity
Attack Type
CWE-73
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading local repositories on the server

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-06T17:17:24.580Z",
  "pubdate": "2026-10-06T17:17:24.580Z",
  "executiveSummary": "A critical vulnerability exists in JetBrains TeamCity versions prior to 2026.2.1 concerning improper validation of Git submodule URLs.\nThe vulnerability allows an authenticated attacker to perform unauthorized file system reads on the TeamCity server by manipulating Git submodule configurations.\nBy crafting a malicious repository containing a submodule with a path targeting local files, an attacker can trick the server into accessing unauthorized sensitive data stored on the host machine.\nThis flaw effectively bypasses intended repository isolation mechanisms, leading to potential exposure of configuration files, credentials, or other sensitive system artifacts.\nThe impact is significant, as it permits unauthorized access to the underlying server environment from the context of an application repository.\nExploitation requires the ability to define or influence Git repository configurations that the TeamCity server subsequently processes during the cloning or synchronization phase.\nGiven that this involves arbitrary file access on the host server, the risk is classified as high, necessitating immediate attention and patching to the specified secure version.",
  "technicalDetails": "The root cause of this vulnerability is a failure in the input validation logic responsible for sanitizing Git submodule URLs within the TeamCity server's repository management component.\nGit allows submodule definitions to reference external repositories via various protocols and paths. In the vulnerable versions of JetBrains TeamCity, the server-side logic processes these submodule definitions without adequately restricting the URI schemas or verifying the resolution path of the target.\nSpecifically, when TeamCity executes Git commands to pull submodules, it acts as the client agent. If a repository contains a maliciously crafted .gitmodules file, an attacker can specify a local file path instead of a legitimate remote repository URL.\nThe attack flow proceeds as follows: First, an attacker creates or modifies a Git repository to include a .gitmodules entry where the 'url' parameter is pointed to a local filesystem path on the TeamCity server, often utilizing file:// protocols or direct path references if the underlying git binary allows it. Second, the attacker triggers a repository synchronization or build process in TeamCity that initiates a 'git submodule update' command.\nBecause the server fails to validate the requested URL, it attempts to access the local file path as if it were a valid Git repository source. Depending on the server's Git configuration and the specific implementation of the submodule parser, the process may attempt to read the content of the target file or directory into the server's workspace.\nThis behavior results in unauthorized local file disclosure. If the attacker targets sensitive files, such as configuration files containing secret keys, private keys, or environment variables, those files could be copied into the TeamCity build workspace, from where the attacker could retrieve the content via build logs or artifact storage.\nThis exploit is particularly dangerous because it leverages the legitimate functionality of the build server to interact with the local filesystem, effectively turning the server's own Git engine into an instrument for directory traversal or arbitrary file read.\nThe vulnerability affects all JetBrains TeamCity installations prior to version 2026.2.1. Protection relies on strict input validation to ensure that submodule URLs point exclusively to expected, sanitized, and remote network locations, preventing the transition to local filesystem references."
}
CVE-2026-106219: TeamCity Git Submodule Path Traversal (MEDIUM Severity, CVSS: 6.5) | Sceawere