magicmirror has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 4. The median CVSS is 4.3 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.3
- Publish → KEV
- —
- Last 90 days
- 4 prev 0
Worst active — by depth score
CVE-2026-63642MediumMagicMirror² is an open source modular smart mirror platform40CVE-2026-63643MediumMagicMirror² is an open source modular smart mirror platform28CVE-2026-63640Medium· 4.3MagicMirror² is an open source modular smart mirror platform24CVE-2026-63641LowMagicMirror² is an open source modular smart mirror platform14
magicmirror vulnerabilities
CVEs affecting magicmirror, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-63641LowMagicMirror² is an open source modular smart mirror platform
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equival…
CVE-2026-63642MediumPoCMagicMirror² is an open source modular smart mirror platform
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed…
CVE-2026-63643MediumMagicMirror² is an open source modular smart mirror platform
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through…
CVE-2026-63640Medium· 4.3MagicMirror² is an open source modular smart mirror platform
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder i…