🔐 CVE Alert

CVE-2026-63641

UNKNOWN 0.0

MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.

CWE CWE-284
Vendor magicmirrororg
Product magicmirror
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for magicmirrororg magicmirror

Be the first to know when new unknown vulnerabilities affecting magicmirrororg magicmirror are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

MagicMirrorOrg / MagicMirror
< 2.37.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-w26r-fwg8-rcp3 github.com: https://github.com/MagicMirrorOrg/MagicMirror/pull/4169 github.com: https://github.com/MagicMirrorOrg/MagicMirror/commit/58c2a5e675a7d367b64d72e1d35680d202ff5c9f github.com: https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.37.0