---
id: CVE-2026-63640
title: MagicMirror² is an open source modular smart mirror platform
summary: >-
  MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0,
  when hideConfigSecrets is enabled, the catch-all socket dispatcher in
  js/node_helper.js passes every inbound object payload through
  replaceSecretPlaceholder i…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: magicmirror
product: magicmirror
affected:
  - magicmirror < 2.37.0
patched:
  - magicmirror 2.37.0
published: '2026-08-18'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T21:02:26.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-63640'
references:
  - url: >-
      https://github.com/MagicMirrorOrg/MagicMirror/commit/ca7b752025962441196e148f8c1bc04b90117979
    label: security-advisories@github.com
  - url: 'https://github.com/MagicMirrorOrg/MagicMirror/pull/4184'
    label: security-advisories@github.com
  - url: 'https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.37.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-q4gh-4ffp-5cg8
    label: security-advisories@github.com
  - url: >-
      https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-q4gh-4ffp-5cg8
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://github.com/advisories/GHSA-q4gh-4ffp-5cg8'
tags:
  - nvd
  - ghsa
  - npm
epss: 0.00298
epssPercentile: 0.20014
aliases:
  - GHSA-q4gh-4ffp-5cg8
ecosystem: npm
ingestedAt: '2026-08-18T18:21:29.733Z'
---

## Overview

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder in js/server_functions.js before invoking socketNotificationReceived. A client connected to a loaded module namespace can submit a SECRET_API_KEY placeholder, causing the server to replace it with the corresponding process environment value. The default weather helper accepts INIT_WEATHER, copies the attacker-controlled instanceId, and returns it in WEATHER_ERROR, providing an echo path for the expanded secret. This reverses the intended one-way redaction boundary and can disclose API tokens, credentials, or service keys stored in SECRET_ variables. This issue is fixed in version 2.37.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-63640)

Affected packages:

- `magicmirror < 2.37.0`

Patched in:

- `magicmirror 2.37.0`

Source: https://github.com/advisories/GHSA-q4gh-4ffp-5cg8
