MagicMirror是MagicMirror开源的一个模块化智能镜面平台。 MagicMirror 2.36.0之前版本存在代码问题漏洞,该漏洞源于/cors端点存在未认证的服务端请求伪造,可能导致任何远程攻击者强制MagicMirror²服务器对内部网络、云元数据服务和本地主机服务执行任意HTTP请求,端点还扩展环境变量占位符,导致服务器端秘密泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MagicMirrorOrg | MagicMirror | < 2.36.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MagicMirrorOrg | MagicMirror | < 2.36.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (VAR_NAME), enabling exfiltration of server-side secrets. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-42281.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet