Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-25228

Опубликовано: 02 фев. 2026
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.20.3, a path traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The validateAppId() function blocks forward slashes (/) but not backslashes (), which are treated as directory separators by path.join() on Windows. This enables attackers to escape the intended applicationData directory. This vulnerability is fixed in 2.20.3.

EPSS

Процентиль: 1%
0.00011
Низкий

5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5
github
5 дней назад

SignalK Server has Path Traversal leading to information disclosure

EPSS

Процентиль: 1%
0.00011
Низкий

5 Medium

CVSS3

Дефекты

CWE-22