Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-w26r-fwg8-rcp3 | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions |
Tue, 18 Aug 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magicmirrororg
Magicmirrororg magicmirror |
|
| Vendors & Products |
Magicmirrororg
Magicmirrororg magicmirror |
Tue, 18 Aug 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0. | |
| Title | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-18T19:26:23.631Z
Reserved: 2026-07-17T14:11:15.483Z
Link: CVE-2026-63641
No data.
Status : Received
Published: 2026-08-18T18:19:11.963
Modified: 2026-08-18T18:19:11.963
Link: CVE-2026-63641
No data.
OpenCVE Enrichment
Updated: 2026-08-18T19:00:12Z
Github GHSA