Unvalidated URL Fetch Vulnerability in MagicMirror² by MagicMirrorOrg
CVE-2026-63642

6.3MEDIUM

Key Information:

Vendor
CVE Published:
18 August 2026

What is CVE-2026-63642?

The MagicMirror² platform, an open-source smart mirror solution, contains a vulnerability where the checkArticleUrl function within the defaultmodules/newsfeed/node_helper.js file accepts unchecked URLs via the unauthenticated Socket.IO namespace '/newsfeed'. This oversight allows an attacker to perform a fetch operation on an arbitrary URL without validation, potentially revealing sensitive internal network details and triggering unintended side effects on services that respond to HEAD requests. The issue has been addressed in version 2.37.0.

Affected Version(s)

MagicMirror < 2.37.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.