CVE-2026-23515 | SignalK signalk-server up to 1.4.x Delta Message navigation.datetime os command injection (GHSA-p8gp-2w28-mhwg)
A vulnerability marked as critical has been reported in SignalK signalk-server up to 1.4.x. This affects an unknown function of the component Delta Message Handler. This manipulation of the argument navigation.datetime causes os command injection.
The identification of this vulnerability is CVE-2026-23515. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.