SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-63641

LOW · CVSS 2.3 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

MagicMirror² versions prior to 2.37.0 are vulnerable due to insufficient IP allowlisting and authentication checks on the Socket.IO server, allowing unauthenticated adjacent-network clients to connect and dispatch arbitrary events. This can lead to exposure of internal services, manipulation of module states, and execution of commands via server-side requests, posing a risk to the integrity and security of the system. Users operating non-loopback deployments should prioritize upgrading to version 2.37.0 to mitigate these vulnerabilities.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63641
Severity
LOW
CVSS
2.3
EPSS
0.48%

Original NVD Description

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.