CVE-2026-25228 | SignalK signalk-server up to 2.20.2 on Windows validateAppId path traversal (GHSA-vrhw-v2hw-jffx)
A vulnerability classified as critical has been found in SignalK signalk-server up to 2.20.2 on Windows. The impacted element is the function validateAppId. This manipulation causes path traversal.
This vulnerability is tracked as CVE-2026-25228. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.