Aller au contenu

Fiche vulnérabilité

CVE-2026-25228 : faille moyenne signalk signal k server (CVSS 4.3)

Description

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The validateAppId() function blocks forward slashes (/) but not backslashes (\), which are treated as directory separators by path.join() on Windows. This enables attackers to escape the intended applicationData directory. This vulnerability is fixed in 2.20.3.

En bref

Sévérité
Moyenne (CVSS 4.3)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
2 févr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • signalk signal k server

Références

Rechercher une autre vulnérabilité dans la base CVE