Unvalidated URL Fetch Vulnerability in MagicMirror² by MagicMirrorOrg
CVE-2026-63642
6.3MEDIUM
What is CVE-2026-63642?
The MagicMirror² platform, an open-source smart mirror solution, contains a vulnerability where the checkArticleUrl function within the defaultmodules/newsfeed/node_helper.js file accepts unchecked URLs via the unauthenticated Socket.IO namespace '/newsfeed'. This oversight allows an attacker to perform a fetch operation on an arbitrary URL without validation, potentially revealing sensitive internal network details and triggering unintended side effects on services that respond to HEAD requests. The issue has been addressed in version 2.37.0.
Affected Version(s)
MagicMirror < 2.37.0
