<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 01:17:43 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-264787</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-264787</link>
      <description>EUVD-2026-264787</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-264787</guid>
    </item>
    <item>
      <title>fkie_cve-2025-68273</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-68273</link>
      <description>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks. Version 2.19.0 patches the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-68273</guid>
    </item>
    <item>
      <title>GHSA-fpf5-w967-rr2m — Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fpf5-w967-rr2m</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;[Note] This is a separate issue from the RCE vulnerability (State Pollution) currently being patched. While related to tokensecurity.js, it involves different endpoints and risks.&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated information disclosure vulnerability allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability stems from the fact that several sensitive API endpoints are not included in the authentication middleware&amp;#39;s protection list in `src/tokensecurity.js`.&lt;/p&gt;
&lt;p&gt;**Vulnerable Code Analysis:**
1.  **Missing Protection**: The `tokensecurity.js` file defines an array of paths that require authentication. However, the following paths defined in `src/serverroutes.ts` are missing from this list:
    - `/skServer/serialports`
    - `/skServer/availablePaths`
    - `/skServer/hasAnalyzer`&lt;/p&gt;
&lt;p&gt;2.  **Unrestricted Access**: Because they are missing from the protection list, the `http_authorize` middleware allows access to these paths even when `enableSecurity` is set to `true`.&lt;/p&gt;
&lt;p&gt;**Exploit Scenario:**
1.  **Reconnaissance**: An attacker scans the server for these endpoints.
2.  **Data Extraction**:
    - Querying `/skServer/availablePaths` returns the full JSON schema of the vessel&amp;#39;s data (e.g., `environment.sun.sunrise`, `navigation.position`), allowing the attacker to know exactly what data points are availabl…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: signalk-server&lt;/p&gt;
&lt;p&gt;[Note] This is a separate issue from the RCE vulnerability (State Pollution) currently being patched. While related to tokensecurity.js, it involves different endpoints and risks.&lt;/p&gt;
&lt;p&gt;### Summary
An unauthenticated information disclosure vulnerability allows any user to retrieve sensitive system information, including the full SignalK data schema, connected serial devices, and installed analyzer tools. This exposure facilitates reconnaissance for further attacks.&lt;/p&gt;
&lt;p&gt;### Details
The vulnerability stems from the fact that several sensitive API endpoints are not included in the authentication middleware&amp;#39;s protection list in `src/tokensecurity.js`.&lt;/p&gt;
&lt;p&gt;**Vulnerable Code Analysis:**
1.  **Missing Protection**: The `tokensecurity.js` file defines an array of paths that require authentication. However, the following paths defined in `src/serverroutes.ts` are missing from this list:
    - `/skServer/serialports`
    - `/skServer/availablePaths`
    - `/skServer/hasAnalyzer`&lt;/p&gt;
&lt;p&gt;2.  **Unrestricted Access**: Because they are missing from the protection list, the `http_authorize` middleware allows access to these paths even when `enableSecurity` is set to `true`.&lt;/p&gt;
&lt;p&gt;**Exploit Scenario:**
1.  **Reconnaissance**: An attacker scans the server for these endpoints.
2.  **Data Extraction**:
    - Querying `/skServer/availablePaths` returns the full JSON schema of the vessel&amp;#39;s data (e.g., `environment.sun.sunrise`, `navigation.position`), allowing the attacker to know exactly what data points are availabl…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fpf5-w967-rr2m</guid>
    </item>
  </channel>
</rss>
