Moderate severityOSV Advisory· Published Feb 2, 2026· Updated Feb 4, 2026
SignalK Server has Path Traversal leading to information disclosure
CVE-2026-25228
Description
Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The validateAppId() function blocks forward slashes (/) but not backslashes (\), which are treated as directory separators by path.join() on Windows. This enables attackers to escape the intended applicationData directory. This vulnerability is fixed in 2.20.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
signalk-servernpm | < 2.20.3 | 2.20.3 |
Affected products
2- Range: 0.1.1, 0.1.10, 0.1.11, …
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vrhw-v2hw-jffxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-25228ghsaADVISORY
- github.com/SignalK/signalk-server/commit/9bcf61c8fe2cb8a40998b913a02fb64dff9e86c7ghsax_refsource_MISCWEB
- github.com/SignalK/signalk-server/security/advisories/GHSA-vrhw-v2hw-jffxghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.