CVE-2026-63643 | MagicMirrorOrg MagicMirror up to 2.36.x Calendar node_helper.js ADD_CALENDAR handler selfSignedCert server-side request forgery

SecurityVulns

A vulnerability, which was classified as critical, has been found in MagicMirrorOrg MagicMirror up to 2.36.x. This affects the function ADD_CALENDAR handler of the file defaultmodules/calendar/node_helper.js of the component Calendar. This manipulation of the argument selfSignedCert causes server-side request forgery.

This vulnerability is handled as CVE-2026-63643. The attack can be initiated remotely. There is not any exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More