Description
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.
Published: 2026-08-18
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MagicMirror is an open‑source smart mirror platform that, prior to version 2.37.0, enforces IP whitelisting only in the Express middleware layer. The Socket.IO server, however, is attached directly to the HTTP server without equivalent IP or origin checks, creating a CWE‑284 improper access control flaw. Because any client on the adjacent network can connect to module Socket.IO namespaces, the node_helper dispatches arbitrary events to socketNotificationReceived. Attackers can trigger server‑side requests from the default newsfeed and calendar helpers or, via the updatenotification helper, invoke child_process.exec when a third‑party module update is pending and the attacker supplies a custom update command through the socket CONFIG path. This allows an attacker to expose internal services, manipulate module state, or conditionally execute arbitrary commands on the host machine.

Affected Systems

The vulnerability affects MagicMirror originated by MagicMirrorOrg. All releases prior to version 2.37.0 are impacted, including 2.36.x and earlier. Administrators should verify that their installation is running a version older than 2.37.0 to determine exposure.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall risk, and the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. A likely attack vector is a local or adjacent network client that bypasses the IP whitelist by connecting directly to the Socket.IO namespaces. Exploitation requires that the attacker can interact with the MagicMirror instance and that some default helpers are enabled. While the flaw does not provide immediate remote code execution in all scenarios, the ability to trigger child_process.exec via the updatenotification helper makes it a possible local privilege escalation or command execution exploit in vulnerable deployments.

Generated by OpenCVE AI on August 18, 2026 at 18:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MagicMirror to version 2.37.0 or later, which contains the patch that adds IP and namespace authentication checks to the Socket.IO server.
  • Configure firewall or network controls to restrict traffic to the MagicMirror HTTP and Socket.IO ports so that only IP addresses on the configured whitelist can reach the application.
  • Disable or remove the default newsfeed, calendar, and updatenotification helpers if they are not required, and review helper configurations to ensure they validate or restrict external sources before making server‑side requests.

Generated by OpenCVE AI on August 18, 2026 at 18:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w26r-fwg8-rcp3 MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Magicmirrororg
Magicmirrororg magicmirror
Vendors & Products Magicmirrororg
Magicmirrororg magicmirror

Tue, 18 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.
Title MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


Subscriptions

Magicmirrororg Magicmirror
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-08-18T19:26:23.631Z

Reserved: 2026-07-17T14:11:15.483Z

Link: CVE-2026-63641

cve-icon Vulnrichment

Updated: 2026-08-18T19:26:19.352Z

cve-icon NVD

Status : Received

Published: 2026-08-18T18:19:11.963

Modified: 2026-08-18T20:17:20.180

Link: CVE-2026-63641

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T19:00:12Z

Weaknesses