Vulnerabilities/

Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints

Severity:
Medium

Description

[Note] This is a separate issue from the RCE vulnerability (State Pollution) currently being patched. While related to tokensecurity.js, it involves different endpoints and risks.

Recommendation

Update the signalk-server package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
signalk-server
Anything's wrong? Let us know Last updated on January 02, 2026