THREAT OPS › Threat News › [GHSA] GHSA-w26r-fwg8-rcp3 (low) — MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
[GHSA] GHSA-w26r-fwg8-rcp3 (low) — MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
GHSA-w26r-fwg8-rcp3 Severity: low CVE: CVE-2026-63641
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
### Summary MagicMirror applies `ipWhitelist` only as Express middleware, but the Socket.IO server is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a docume
Indicators of compromise
- fb41d24ef522e91e802e2a623ff6afbddeb3c9d8sha1
- CVE-2026-63641cve
- http://127.0.0.1:65535/internalurl
- http://127.0.0.1:65535/internal`url
Original source: https://github.com/advisories/GHSA-w26r-fwg8-rcp3