CVE-2026-63641 | MagicMirrorOrg MagicMirror up to 2.36.9 Socket.IO server js/node_helper.js socketNotificationReceived CONFIG server-side request forgery
A vulnerability has been found in MagicMirrorOrg MagicMirror up to 2.36.9 and classified as critical. Affected is the function socketNotificationReceived of the file js/node_helper.js of the component Socket.IO server. Performing a manipulation of the argument CONFIG results in server-side request forgery.
This vulnerability was named CVE-2026-63641. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.VulDB Recent EntriesRead More