Remote Code Execution Vulnerability in Signal K Server by Signal K
CVE-2026-55591
What is CVE-2026-55591?
The Signal K Server, a central application for marine environments, is prone to a remote code execution vulnerability that allows attackers to exploit endpoints without adequate validation of input parameters. Specifically, functions such as makeRemoteRequest() can accept tampered host, port, useTLS, and selfsignedcert values, leading to unauthorized access to internal services and sensitive data exfiltration. Additionally, the failure in security configurations means certain endpoints lack authentication, further exacerbating the issue. This vulnerability enables potential internal port scanning and unauthorized HTTP requests to untrusted destinations. The issue has been resolved in version 2.28.0. Users are urged to update their installations promptly to mitigate risks.
Affected Version(s)
signalk-server < 2.28.0
