CVE-2025-68619 describes an arbitrary code execution vulnerability in Signal K Server versions prior to 2.19.0. An authenticated administrator can leverage a REST API endpoint designed for installing npm packages. The vulnerability arises because the application passes unsanitized version specifiers, including URLs, directly to npm, allowing the installation of malicious packages with postinstall scripts. This vulnerability is rated High severity (CVSS 7.2) due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. An attacker with administrative credentials can achieve arbitrary code execution on the server. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.19.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:* | ||
2.19.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.19.0:beta1:*:*:*:*:*:* | ||
2.19.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.19.0:beta2:*:*:*:*:*:* | ||
2.19.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.19.0:beta3:*:*:*:*:*:* | ||
2.19.0CPE matchmatch criteria | cpe:2.3:a:signalk:signal_k_server:2.19.0:beta4:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.