Back

MEDIUM

MagicMirror: ssrf calendar .js

Published Aug 18, 2026

Description

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through the unauthenticated Socket.IO namespace /calendar. The handler passes these fields to CalendarFetcher, causing a server-side request without SSRF validation and optionally disabling TLS verification. When the response is valid iCal, CALENDAR_EVENTS returns parsed event data to the attacker, allowing internal-service response data to be exfiltrated; other responses still provide a blind request and timing primitive. This issue is fixed in version 2.37.0.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 18, 2026
Updated Aug 19, 2026
Reserved Jul 17, 2026
CISA Vulnrichment
Updated Aug 19, 2026
NVD
Status Deferred
Modified Sep 8, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-W6X9-28JW-HQ7J