THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w26r-fwg8-rcp3 (low) — MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions

[GHSA] GHSA-w26r-fwg8-rcp3 (low) — MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions

highgithub_advisoriesPublished 2026-08-18

GHSA-w26r-fwg8-rcp3 Severity: low CVE: CVE-2026-63641

MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions

### Summary MagicMirror applies `ipWhitelist` only as Express middleware, but the Socket.IO server is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a docume

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w26r-fwg8-rcp3