PT-2026-77238 · Unknown · Magicmirror
CVE-2026-63643
·
Published
2026-08-18
·
Updated
2026-08-18
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MagicMirror² versions prior to 2.37.0
Description
The
ADD CALENDAR handler in defaultmodules/calendar/node helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through the unauthenticated Socket.IO namespace /calendar. The handler passes these fields to CalendarFetcher, resulting in a server-side request without Server-Side Request Forgery (SSRF) validation—a flaw where a server is tricked into making requests to an unintended location—and optionally disabling TLS verification. If the response is valid iCal, CALENDAR EVENTS returns parsed event data to the attacker, enabling the exfiltration of internal-service response data. Other responses still allow for a blind request and timing primitive.Recommendations
Update to version 2.37.0.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Magicmirror