CVE-2026-23515
CRITICALSignal K Server <1.5.0 - Command Injection
Title source: llmDescription
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server when the set-system-time plugin is enabled. Unauthenticated users can also exploit this vulnerability if security is disabled on the Signal K server. This occurs due to unsafe construction of shell commands when processing navigation.datetime values received via WebSocket delta messages. This vulnerability is fixed in 1.5.0.
Scores
CVSS v3
9.9
EPSS
0.0496
EPSS Percentile
89.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Classification
CWE
CWE-78
Status
published
Affected Products (2)
signalk/set-system-time
< 1.5.0npm
signalk/signal_k_server
< 1.5.0
Timeline
Published
Feb 02, 2026
Tracked Since
Feb 18, 2026