All 5 CVE vulnerabilities found in MagicMirror, with AI-generated Chinese analysis, references, and POCs.
Vendor: MagicMirrorOrg
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-63640 | MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables CWE-200 | 4.3 | Medium | 2026-08-18 |
| CVE-2026-63642 | MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery CWE-918 | 6.3 | Medium | 2026-08-18 |
| CVE-2026-63643 | MagicMirror: ssrf calendar .js CWE-918 | 6.3 | Medium | 2026-08-18 |
| CVE-2026-63641 | MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions CWE-284 | 2.3 | Low | 2026-08-18 |
| CVE-2026-42281 | MagicMirror²: Unauthenticated SSRF via /cors endpoint CWE-918 | - | - | 2026-05-14 |
All 5 known CVE vulnerabilities affecting MagicMirror with full Chinese analysis, references, and POCs where available.