IP Allowlist Vulnerability in MagicMirror² Open Source Platform
CVE-2026-63641

2.3LOW

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-63641?

MagicMirror², a popular open-source smart mirror platform, was found to lack sufficient security on its Socket.IO server. Versions prior to 2.37.0 apply IP whitelisting only as middleware, directly exposing Socket.IO namespaces to unauthorized adjacent-network clients. This flaw allows attackers to interact with internal modules unchecked, executing arbitrary commands and potentially exposing sensitive services. The vulnerability stems from the absence of authentication checks on Socket.IO connections, enabling potential exploitation via common helpers that fetch data from attacker-controlled URLs. The issue has been addressed and resolved in version 2.37.0.

Affected Version(s)

MagicMirror < 2.37.0

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.