CVE-2026-63643 | MagicMirrorOrg MagicMirror up to 2.36.x Calendar node_helper.js ADD_CALENDAR handler selfSignedCert server-side request forgery
A vulnerability, which was classified as critical, has been found in MagicMirrorOrg MagicMirror up to 2.36.x. This affects the function ADD_CALENDAR handler of the file defaultmodules/calendar/node_helper.js of the component Calendar. This manipulation of the argument selfSignedCert causes server-side request forgery.
This vulnerability is handled as CVE-2026-63643. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More