VulnSea

magicmirror vulnerabilities

CVEs whose affected-version data names the magicmirror package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-63641Low
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equival…

Sunlitmagicmirror · magicmirrorEPSS 0.48%via NVD
CVE-2026-63642MediumPoC
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed…

Twilightmagicmirror · magicmirrorEPSS 0.46%via NVD
CVE-2026-63643Medium
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through…

Sunlitmagicmirror · magicmirrorEPSS 0.47%via NVD
CVE-2026-63640Medium· 4.3
1mo ago

MagicMirror² is an open source modular smart mirror platform

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder i…

Sunlitmagicmirror · magicmirrorEPSS 0.32%via NVD
magicmirror vulnerabilities (CVEs) · VulnSea