{"id":"CVE-2025-66398","title":"Signal K Server is a server application that runs on a central hub in a boat","summary":"Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoi…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-78","CWE-913"],"vendor":"signalk","product":"signal_k_server","affected":["signal_k_server < 2.19.0"],"patched":["signal_k_server 2.19.0"],"published":"2026-01-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T08:10:00.183","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-66398","references":[{"url":"https://github.com/SignalK/signalk-server/releases/tag/v2.19.0","label":"security-advisories@github.com"},{"url":"https://github.com/SignalK/signalk-server/security/advisories/GHSA-w3x5-7c4c-66p9","label":"security-advisories@github.com"}],"tags":["nvd","exploit-available"],"epss":0.1985,"epssPercentile":0.97338,"exploits":{"github":2,"githubRepos":["https://github.com/joshuavanderpoll/cve-2025-66398","https://github.com/showy-headteacher114/cve-2025-66398"],"checkedAt":"2026-10-01T08:40:45.230Z"},"exploitAvailable":true,"ingestedAt":"2026-10-01T08:40:11.723Z","slug":"CVE-2025-66398","body":"## Overview\n\nSignal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoint. This allows the attacker to hijack the administrator's \"Restore\" functionality to overwrite critical server configuration files (e.g., `security.json`, `package.json`), leading to account takeover and Remote Code Execution (RCE). Version 2.19.0 patches this vulnerability.\n\n## Affected\n\n- `signal_k_server < 2.19.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `signal_k_server 2.19.0`","depth":"abyssal","depthScore":69,"depthScoreParts":{"impact":52.8,"likelihood":4,"exploitation":12,"ransomware":0},"changes":[]}