CVE-2025-66398 | SignalK Server up to 2.18.x /skServer/validateBackup os command injection (EUVD-2025-206140)
A vulnerability described as critical has been identified in SignalK Server up to 2.18.x. This affects an unknown function of the file /skServer/validateBackup. Executing manipulation can lead to os command injection.
This vulnerability appears as CVE-2025-66398. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.