Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w3x5-7c4c-66p9 | Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE) |
Tue, 06 Jan 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signalk signal K Server
|
|
| CPEs | cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Signalk signal K Server
|
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signalk
Signalk signalk-server |
|
| Vendors & Products |
Signalk
Signalk signalk-server |
Thu, 01 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's "Restore" functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability. | |
| Title | Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE) | |
| Weaknesses | CWE-78 CWE-913 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-05T21:00:41.972Z
Reserved: 2025-11-28T23:33:56.363Z
Link: CVE-2025-66398
Updated: 2026-01-05T21:00:37.636Z
Status : Analyzed
Published: 2026-01-01T18:15:40.550
Modified: 2026-01-06T18:34:31.007
Link: CVE-2025-66398
No data.
OpenCVE Enrichment
Updated: 2026-01-05T10:14:48Z
Github GHSA