---
id: CVE-2025-68273
title: Signal K Server is a server application that runs on a central hub in a boat
summary: >-
  Signal K Server is a server application that runs on a central hub in a boat.
  An unauthenticated information disclosure vulnerability in versions prior to
  2.19.0 allows any user to retrieve sensitive system information, including the
  ful…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: signalk
product: signal_k_server
affected:
  - signal_k_server < 2.19.0
patched:
  - signal_k_server 2.19.0
published: '2026-01-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:10:00.183'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68273'
references:
  - url: 'https://github.com/SignalK/signalk-server/releases/tag/v2.19.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/SignalK/signalk-server/security/advisories/GHSA-fpf5-w967-rr2m
    label: security-advisories@github.com
tags:
  - nvd
  - exploit-available
epss: 0.00823
epssPercentile: 0.55646
exploits:
  nuclei:
    - CVE-2025-68273
  checkedAt: '2026-10-01T08:40:45.230Z'
exploitAvailable: true
ingestedAt: '2026-10-01T08:40:11.724Z'
---

## Overview

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.

## Affected

- `signal_k_server < 2.19.0`

## Remediation

Upgrade past the affected range:

- `signal_k_server 2.19.0`
