GHSA-c3h4-9gc2-f7h4 · Severity: high · Ecosystem: nuget — tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .dme files existing on the host machine to be compiled and executed. These .dme files could be uploaded via tgstation-server (requiring a separate, isolated privilege) or some other means. A server configured to execute in BYOND's trusted security level (requiring a third separate, isolated privilege OR being set by another user) could lead to this escalating into remote code execution via BYOND's shell() proc. The ability to execute this kind of attack is a known side effect of having privileged TGS users, but normally requires multiple privileges with known weaknesses. This vector is not intentional as it does not require control over the where deployment code is sourced from and _may_ not require remote write access to an instance's `Configuration` directory. This problem is fixed in versions 6.8.0 and above.
Conclusion & alert: CVE-2024-41799 is rated High Risk (67.2/100): CVSS High severity, with high exploitation likelihood (EPSS 7.02%, 91th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.73% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-18 | 5.30% | 7.02% | +1.73% |
| 2 | 2025-11-21 | 2.25% | 5.30% | +3.05% |
| 3 | 2025-11-18 | — | 2.25% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.4 | 3.1 | HIGH |
|
1.8 | 6.0 | [email protected] |
| 9.9 | 3.1 | CRITICAL |
|
3.1 | 6.0 | [email protected] |
GHSA-c3h4-9gc2-f7h4 · Severity: high · Ecosystem: nuget — tgstation-server's DreamMaker environment files outside the deployment directory can be compiled and ran by insufficiently permissioned users
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| tgstation13 | tgstation-server | >= 4.0.0, < 6.8.0 | cpe:2.3:a:tgstation13:tgstation-server:*:*:*:*:*:*:*:* |