CVE-2026-63642 | MagicMirrorOrg MagicMirror up to 2.36.x Newsfeed node_helper.js checkArticleUrl CHECK_ARTICLE_URL server-side request forgery
A vulnerability marked as critical has been reported in MagicMirrorOrg MagicMirror up to 2.36.x. This issue affects the function checkArticleUrl of the file defaultmodules/newsfeed/node_helper.js of the component Newsfeed. Performing a manipulation of the argument CHECK_ARTICLE_URL results in server-side request forgery.
This vulnerability is reported as CVE-2026-63642. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More