CVE advisoryCRITICAL
CVE-2025-68620
Signal K Server JWT Token Theft Vulnerability
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
A critical vulnerability in Signal K Server allows unauthenticated attackers to steal JWT authentication tokens by chaining two features. This could lead to unauthorized access and hijacking of legitimate device credentials. Readers should verify if Signal K Server is deployed and assess its network exposure and operat