CVE-2026-63641: CWE-284: Improper Access Control in MagicMirrorOrg MagicMirror
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.
AI Analysis
Technical Summary
MagicMirror² is an open source smart mirror platform. Before version 2.37.0, the ipWhitelist was applied only as Express middleware, but the Socket.IO server was attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication. This flaw allows an unauthenticated client on an adjacent network to connect to Socket.IO namespaces and dispatch arbitrary events to socketNotificationReceived. Default helpers like newsfeed and calendar can make server-side requests to attacker-controlled URLs, and the updatenotification helper can execute commands via child_process.exec if an attacker supplies an update command through the socket CONFIG path. This vulnerability exposes internal services, allows manipulation of module-helper state, and conditional command execution. The vulnerability is resolved in MagicMirror version 2.37.0.
Potential Impact
An unauthenticated attacker on an adjacent network can bypass intended IP whitelist restrictions and interact directly with the Socket.IO server namespaces. This can lead to exposure of internal services, manipulation of module-helper state, and conditional execution of commands on the server. The default modules can be abused to make server-side requests to attacker-controlled URLs and execute commands, increasing the risk of unauthorized access and potential system compromise. The CVSS score is low (2.3), indicating limited impact or exploitability conditions.
Mitigation Recommendations
Upgrade MagicMirror to version 2.37.0 or later, where this improper access control vulnerability is fixed. No other official remediation or temporary fixes are documented. Until upgrading, restrict network access to trusted clients only to reduce exposure.
CVE-2026-63641: CWE-284: Improper Access Control in MagicMirrorOrg MagicMirror
Description
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.
CVSS v4.0
Score 2.3low
Affected software
pkg:github/magicmirrororg/MagicMirrorRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MagicMirror² is an open source smart mirror platform. Before version 2.37.0, the ipWhitelist was applied only as Express middleware, but the Socket.IO server was attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication. This flaw allows an unauthenticated client on an adjacent network to connect to Socket.IO namespaces and dispatch arbitrary events to socketNotificationReceived. Default helpers like newsfeed and calendar can make server-side requests to attacker-controlled URLs, and the updatenotification helper can execute commands via child_process.exec if an attacker supplies an update command through the socket CONFIG path. This vulnerability exposes internal services, allows manipulation of module-helper state, and conditional command execution. The vulnerability is resolved in MagicMirror version 2.37.0.
Potential Impact
An unauthenticated attacker on an adjacent network can bypass intended IP whitelist restrictions and interact directly with the Socket.IO server namespaces. This can lead to exposure of internal services, manipulation of module-helper state, and conditional execution of commands on the server. The default modules can be abused to make server-side requests to attacker-controlled URLs and execute commands, increasing the risk of unauthorized access and potential system compromise. The CVSS score is low (2.3), indicating limited impact or exploitability conditions.
Mitigation Recommendations
Upgrade MagicMirror to version 2.37.0 or later, where this improper access control vulnerability is fixed. No other official remediation or temporary fixes are documented. Until upgrading, restrict network access to trusted clients only to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-17T14:11:15.483Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a84980ec6e8be0332896e0f
Added to database: 08/18/2026, 17:36:14 UTC
Last enriched: 08/18/2026, 17:54:57 UTC
Last updated: 08/18/2026, 19:35:11 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.