CVE-2025-21611 - CVE House
Back to Database
Status published High CVE-2025-21611

tgstation-server's role authorization incorrectly OR'd with user's enabled status

Vulnerability Description

tgstation-server is a production scale tool for BYOND server management. Prior to 6.12.3, roles used to authorize API methods were incorrectly OR'd instead of AND'ed with the role used to determine if a user was enabled. This allows enabled users access to most, but not all, authorized actions regardless of their permissions. Notably, the WriteUsers right is unaffected so users may not use this bug to permanently elevate their account permissions. The fix is release in tgstation-server-v6.12.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-21611

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tgstation-server
Vulnerable Versions:
>= 6.11.0, < 6.12.3

Timeline

Official Publish: January 6th, 2025
Last Modified: January 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)