HIGHNuGet →
tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
Affected packages
- Tgstation.Server.Api— 4.0.0 → 6.8.0
- Tgstation.Server.Host— 4.0.0 → 6.8.0
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/tgstation/tgstation-server/security/advisories/GHSA-c3h4-9gc2-f7h4
- https://nvd.nist.gov/vuln/detail/CVE-2024-41799
- https://github.com/tgstation/tgstation-server/pull/1835
- https://github.com/tgstation/tgstation-server/commit/374852fe5ae306415eb5aafb2d16b06897d7afe4
- https://github.com/tgstation/tgstation-server
Structured record: https://osv.dev/vulnerability/GHSA-c3h4-9gc2-f7h4
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta