magicmirror
npm5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting magicmirrorpage 1 of 1
- CVE-2026-42281HIGHCVSS 8.6EG 8.6✓ Fixed in 2.36.02026-05-14
MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perfo…
- CVE-2026-63640MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.37.02026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder in…
- CVE-2026-63641LOWCVSS 2.3EG 2.3✓ Fixed in 2.37.02026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivale…
- CVE-2026-63642MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.37.02026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed …
- CVE-2026-63643MEDIUMCVSS 6.3EG 6.3✓ Fixed in 2.37.02026-08-18
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through …
Check whether magicmirror is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for magicmirror CVEs against the assets you own.
Start Free Scan →