CVE-2026-35038
Severity CVSS v4.0:
LOW
Type:
CWE-20
Input Validation
Publication date:
02/04/2026
Last modified:
29/04/2026
Description
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.24.0, there is an arbitrary prototype read vulnerability via `from` field bypass. This vulnerability allows a low-privileged authenticated user to bypass prototype boundary filtering to extract internal functions and properties from the global prototype object this violates data isolation and lets a user read more than they should. This issue has been patched in version 2.24.0.
Impact
Base Score 4.0
2.10
Severity 4.0
LOW
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:signalk:signal_k_server:*:*:*:*:*:*:*:* | 2.24.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



