CyberRota Analysis
AI-GeneratedMagicMirror² versions prior to 2.37.0 are vulnerable due to insufficient IP allowlisting and authentication checks on the Socket.IO server, allowing unauthenticated adjacent-network clients to connect and dispatch arbitrary events. This can lead to exposure of internal services, manipulation of module states, and execution of commands via server-side requests, posing a risk to the integrity and security of the system. Users operating non-loopback deployments should prioritize upgrading to version 2.37.0 to mitigate these vulnerabilities.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0.