Junglewise Threat Intelligence

CVE-2025-69203: Signal K Server access request spoofing via X-Forwarded-For header

CVE-2025-69203 · Severity: low · CVSS 3.1 · Published 2026-01-02

Technologies: Signal K Server, signalk-server (npm). Vendors: Signal K, npm.

Executive brief

Signal K Server is a marine data server that manages device connections and access permissions. An attacker can craft a malicious access request that appears legitimate to administrators by spoofing the source IP address, providing a misleading description while requesting elevated permissions, and impersonating known devices. This could result in an administrator inadvertently granting admin-level access to an attacker with minimal user interaction.

Technical details

The vulnerability is a combination of insufficient input validation and unvalidated trust of the X-Forwarded-For HTTP header in the access request handler (src/tokensecurity.js). An attacker can craft an access request with a misleading description that suggests limited permissions while actually requesting admin-level access, and spoof their IP address to appear as a trusted internal source. The admin UI (packages/server-admin-ui/src/views/security/AccessRequests.js) displays the description field prominently while de-emphasizing the actual permissions field, increasing the likelihood of approval. The vulnerability requires admin interaction to approve the spoofed request but is highly convincing when combined with device enumeration. Patches are available in Signal K Server 2.19.0 and later.

Affected products

  • Signal K Server <= 2.19.0-beta.4

Timeline

  • 2026-01-02: disclosed
  • 2026-01-02: patched: Fixed in version 2.19.0

References

Related threats