Vendorstgstation13tgstation-serverall versions
Vulnerabilities

tgstation13 tgstation-server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2024-41799
tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
Published 2024-07-29 · Analyzed
9.9EPSS 0.012
CVE-2018-17107
In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subsequent logins to succeed with any username or password.
Published 2018-09-24 · Modified
9.8EPSS 0.016
CVE-2025-21611
tgstation-server's role authorization incorrectly OR'd with user's enabled status
Published 2025-01-06 · Analyzed
8.8EPSS 0.005
CVE-2020-16136
In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server process) via directory traversal ../ sequences in /Administration/Logs/ requests. The attacker is unable to enumerate files, however.
Published 2020-07-31 · Modified
7.7EPSS 0.021
CVE-2023-32687
Insufficiently Protected ChatBot Credentials in tgstation-server
Published 2023-05-29 · Modified
7.7EPSS 0.006
CVE-2023-33198
Incorrectly Specified Chat Message Destinations in tgstation-server and DreamMaker API
Published 2023-05-30 · Modified
7.5EPSS 0.006
CVE-2023-34243
Windows user name disclosure in TGstation
Published 2023-06-08 · Modified
5.8EPSS 0.005