Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-63640— MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables

Quick assessment

Affected
MagicMirrorOrg MagicMirror
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MagicMirror是MagicMirror社区的一款可显示天气、日历等信息的智能镜子。 MagicMirror 2.37.0之前版本存在信息泄露漏洞,该漏洞源于js/node_helper.js中的socket dispatcher在调用socketNotificationReceived前将入站对象payload传递给js/server_functions.js中的replaceSecretPlaceholder处理,导致SECRET_API_KEY占位符被替换为进程环境值,并可通过WEATHER_

CVSS 4.3 · Medium EPSS 0.21% · P11

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

VendorProduct Version RangeStatus
MagicMirrorOrg MagicMirror < 2.37.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-63640

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
Source: CVE Program / CVE List V5
Vulnerability Description
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder in js/server_functions.js before invoking socketNotificationReceived. A client connected to a loaded module namespace can submit a SECRET_API_KEY placeholder, causing the server to replace it with the corresponding process environment value. The default weather helper accepts INIT_WEATHER, copies the attacker-controlled instanceId, and returns it in WEATHER_ERROR, providing an echo path for the expanded secret. This reverses the intended one-way redaction boundary and can disclose API tokens, credentials, or service keys stored in SECRET_ variables. This issue is fixed in version 2.37.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
MagicMirror 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
MagicMirror是MagicMirror社区的一款可显示天气、日历等信息的智能镜子。 MagicMirror 2.37.0之前版本存在信息泄露漏洞,该漏洞源于js/node_helper.js中的socket dispatcher在调用socketNotificationReceived前将入站对象payload传递给js/server_functions.js中的replaceSecretPlaceholder处理,导致SECRET_API_KEY占位符被替换为进程环境值,并可通过WEATHER_
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
MagicMirrorOrg MagicMirror < 2.37.0 -

II. Public POCs for CVE-2026-63640

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-63640

登录查看更多情报信息。

Patches & Fixes for CVE-2026-63640 (2)

Vendor Advisories for CVE-2026-63640 (1)

Vendor Pages for CVE-2026-63640 (1)

Same Patch Batch · MagicMirrorOrg · 2026-08-18 · 4 CVEs total

CVE-2026-63643 6.3 MEDIUM MagicMirror: ssrf calendar .js
CVE-2026-63642 6.3 MEDIUM MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
CVE-2026-63641 2.3 LOW MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthent

IV. Related Vulnerabilities

V. Comments for CVE-2026-63640

No comments yet


Leave a comment