CVE-2026-23515

CRITICAL

Signal K Server <1.5.0 - Command Injection

Title source: llm

Description

Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values received via WebSocket delta messages. This vulnerability is fixed in 1.5.0.

Scores

CVSS v3 9.9
EPSS 0.0496
EPSS Percentile 89.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-78
Status published

Affected Products (2)

signalk/set-system-time < 1.5.0npm
signalk/signal_k_server < 1.5.0

Timeline

Published Feb 02, 2026
Tracked Since Feb 18, 2026