MagicMirror是MagicMirror社区的一款可显示天气、日历等信息的智能镜子。 MagicMirror 2.37.0之前版本存在服务端请求伪造漏洞,该漏洞源于defaultmodules/calendar/node_helper.js中的ADD_CALENDAR处理器接受攻击者控制的URL、身份验证数据和selfSignedCert设置,导致服务端请求伪造(SSRF)问题,可能允许未经身份验证的攻击者通过/calendar命名空间泄露内部服务响应数据,或执行盲请求和计时探测。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| MagicMirrorOrg | MagicMirror | < 2.37.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| MagicMirrorOrg | MagicMirror | < 2.37.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-63642 | 6.3 MEDIUM | MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery |
| CVE-2026-63640 | 4.3 MEDIUM | MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment |
| CVE-2026-63641 | 2.3 LOW | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthent |
No comments yet