MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Published Aug 18, 2026
2.3
LOWCVSS 4.0
EPSS 0.43%
Description
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.
Affected products
-
- Version < 2.37.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| MagicMirrorOrg | MagicMirror | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
magicmirror
npm
Introduced 0 Fixed 2.37.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | magicmirror | 0 | 2.37.0 |
Remediation
No remediation recorded yet.
References (5)
- https://github.com/MagicMirrorOrg/MagicMirror/commit/58c2a5e675a7d367b64d72e1d35680d202ff5c9f x_refsource_MISC
- https://github.com/MagicMirrorOrg/MagicMirror/pull/4169 x_refsource_MISC
- https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.37.0 x_refsource_MISC
- https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-w26r-fwg8-rcp3 exploitx_refsource_CONFIRM
- https://github.com/advisories/GHSA-w26r-fwg8-rcp3 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/MagicMirrorOrg/MagicMirror/commit/58c2a5e675a7d367b64d72e1d35680d202ff5c9f | x_refsource_MISC | |
| https://github.com/MagicMirrorOrg/MagicMirror/pull/4169 | x_refsource_MISC | |
| https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.37.0 | x_refsource_MISC | |
| https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-w26r-fwg8-rcp3 | exploitx_refsource_CONFIRM | |
| https://github.com/advisories/GHSA-w26r-fwg8-rcp3 | Advisory |
Change history (0)
No recorded changes yet.