MagicMirror
MagicMirrorOrg · 5 CVEs
CVE-2026-63640
MEDIUM
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
Aug 18, 2026
CVE-2026-63642
MEDIUM
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
Aug 18, 2026
CVE-2026-63643
MEDIUM
MagicMirror: ssrf calendar .js
Aug 18, 2026
CVE-2026-63641
LOW
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Aug 18, 2026
CVE-2026-42281
CRITICAL
MagicMirror²: Unauthenticated SSRF via /cors endpoint
May 14, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-63640 | MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables | MEDIUM | 0.30% | Aug 18, 2026 |
| CVE-2026-63642 | MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery | MEDIUM | 0.50% | Aug 18, 2026 |
| CVE-2026-63643 | MagicMirror: ssrf calendar .js | MEDIUM | 0.66% | Aug 18, 2026 |
| CVE-2026-63641 | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions | LOW | 0.43% | Aug 18, 2026 |
| CVE-2026-42281 | MagicMirror²: Unauthenticated SSRF via /cors endpoint | CRITICAL | 1.68% | May 14, 2026 |
Showing 1 to 5 of 5 CVEs