signalk security advisories
2 threat alerts tracking vulnerabilities and security advisories that affect signalk products.
Vulnios monitors signalk CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent signalk security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2025-66398 — signalk — signal_k_server
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via
criticalCVE-2025-66398Critical Vulnerability: CVE-2025-68620 — signalk — signal_k_server
Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any p
criticalCVE-2025-68620
Track signalk exposure across your environment
Vulnios automatically cross-references your asset inventory against new signalk CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan