Junglewise Threat Intelligence

CVE-2025-68620: Signal K Server JWT token theft via WebSocket enumeration

CVE-2025-68620 · Severity: low · CVSS 3.1 · Published 2026-01-02

Technologies: Signal K Server, signalk-server (npm). Vendors: Signal K, npm.

Executive brief

Signal K Server is an open-source server for marine data integration used on boats and marine systems. The vulnerability allows attackers to steal authentication tokens without any login credentials by combining unauthenticated WebSocket access with open access request APIs. An attacker can obtain admin-level tokens that grant full control of the system, including the ability to install malicious packages, or intercept tokens meant for legitimate devices.

Technical details

This vulnerability combines two design flaws: (1) unauthenticated WebSocket clients connecting with the serverevents=all parameter receive all cached server events including ACCESS_REQUEST entries with request IDs and details, and (2) the access request status endpoint at /signalk/v1/access/requests/:id returns approved requests with JWT tokens in plaintext without requiring authentication. An attacker can enumerate pending requests from the WebSocket stream or create a spoofed request, then poll the endpoint repeatedly until an administrator approves it, at which point the JWT token is revealed. Both the WebSocket enumeration and REST polling endpoints are accessible to unauthenticated and read-only users. The vulnerability enables complete authentication bypass and account hijacking. Signal K Server versions 2.19.0-beta.4 and earlier are affected; version 2.19.0 patches the issue.

Affected products

  • Signal K Server <= 2.19.0-beta.4

Timeline

  • 2026-01-02: disclosed
  • 2026-01-02: patched: Version 2.19.0 released with fix

References

Related threats