Tgstation13 maintains a server hosting and game management platform for Space Station 13, a niche multiplayer game, presenting a narrowly scoped but security-sensitive attack surface. Its vulnerability profile concentrates in the Tgstation Server product and recurs through weakness classes including path traversal, sensitive information exposure, improper authorization, brute-force resistance, and authentication channel misconfiguration—issues typical of web-facing administrative and account-management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tgstation13 over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17107CRITICAL In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subsequent logins to succeed with any username or password. | Sep 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2024-41799CRITICAL tgstation-server is a production scale tool for BYOND server management. Prior to 6.8.0, low permission users using the "Set .dme Path" privilege could potentially set malicious .d | Jul 29, 2024 | 9.9 | 28 | NO | NO |
CVE-2020-16136HIGH In tgstation-server 4.4.0 and 4.4.1, an authenticated user with permission to download logs can download any file on the server machine (accessible by the owner of the server proce | Jul 31, 2020 | 7.7 | 26 | NO | NO |
CVE-2025-21611HIGH tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role | Jan 6, 2025 | 8.8 | 25 | NO | NO |
CVE-2023-33198HIGH tgstation-server is a production scale tool for BYOND server management. The DreamMaker API (DMAPI) chat channel cache can possibly be poisoned by a tgstation-server (TGS) restart | May 30, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-32687MEDIUM tgstation-server is a toolset to manage production BYOND servers. Starting in version 4.7.0 and prior to 5.12.1, instance users with the list chat bots permission can read chat bot | May 29, 2023 | 6.5 | 20 | NO | NO |
CVE-2023-34243MEDIUM TGstation is a toolset to manage production BYOND servers. In affected versions if a Windows user was registered in tgstation-server (TGS), an attacker could discover their usernam | Jun 8, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tgstation13.
Media articles that mention a CVE ID that affects a product developed by Tgstation13 — matched by CVE ID, not by vendor name.