漏洞描述
JetBrains TeamCity < 2026.1.3, 2025.11.7 contains a remote code execution caused by unsafe XStream deserialization in the unauthenticated agent polling protocol. The XStream instance serving /app/agents/v1 is created without NoTypePermission.NONE, so XStream's default type permissions (Throwable, Map and Collection hierarchies) remain in effect next to the TeamCity allowlist. An unauthenticated attacker registers an agent, obtains a TeamCity-AgentSessionId, and posts an XStream XML object graph to /app/agents/v1/commands/error that makes TeamCity write an attacker-controlled file into the webroot. This template writes an arithmetic-canary JSP (no OS command execution) and matches its evaluated output.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。