PT-2026-77238 · Unknown · Magicmirror

CVE-2026-63643

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MagicMirror² versions prior to 2.37.0
Description The ADD CALENDAR handler in defaultmodules/calendar/node helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through the unauthenticated Socket.IO namespace /calendar. The handler passes these fields to CalendarFetcher, resulting in a server-side request without Server-Side Request Forgery (SSRF) validation—a flaw where a server is tricked into making requests to an unintended location—and optionally disabling TLS verification. If the response is valid iCal, CALENDAR EVENTS returns parsed event data to the attacker, enabling the exfiltration of internal-service response data. Other responses still allow for a blind request and timing primitive.
Recommendations Update to version 2.37.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63643
GHSA-W6X9-28JW-HQ7J

Affected Products

Magicmirror