IP Allowlist Vulnerability in MagicMirror² Open Source Platform
CVE-2026-63641
2.3LOW
What is CVE-2026-63641?
MagicMirror², a popular open-source smart mirror platform, was found to lack sufficient security on its Socket.IO server. Versions prior to 2.37.0 apply IP whitelisting only as middleware, directly exposing Socket.IO namespaces to unauthorized adjacent-network clients. This flaw allows attackers to interact with internal modules unchecked, executing arbitrary commands and potentially exposing sensitive services. The vulnerability stems from the absence of authentication checks on Socket.IO connections, enabling potential exploitation via common helpers that fetch data from attacker-controlled URLs. The issue has been addressed and resolved in version 2.37.0.
Affected Version(s)
MagicMirror < 2.37.0
