S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 14, 2026

CVE-2026-42281 Scanner

CVE-2026-42281 Scanner - Server-Side Request Forgery (SSRF) vulnerability in MagicMirror

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsurl
CostFree
3.3k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-42281
9.2
CVSScritical
Exploitable remotely over the internet · no authentication required.

MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (**VAR_NAME**), enabling exfiltration of server-side secrets. This vulnerability is fixed in 2.36.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MagicMirrorby MagicMirrorOrg
< 2.36.0
Updated Sep 10, 2026View on NVD →
Detail

The MagicMirror software is a widely used platform for displaying customizable data and information on mirrors, often utilized in smart homes and retail environments. Primarily designed for developers and tech enthusiasts, it allows for the integration of various modules and extensions to display customized information such as weather updates, news, and calendars. Developers leverage MagicMirror for its ease of use and flexibility in configuring display modules. It offers an open-source platform, supported by a community that contributes to its feature set and performance enhancements. Being a node-based application, it serves both hobbyists and commercial users seeking to create interactive digital displays. Organizations use MagicMirror to engage customers and visitors by providing real-time information in an aesthetic way.

The server-side request forgery (SSRF) vulnerability in MagicMirror <= 2.35.0 allows attackers to induce the server to initiate requests to certain endpoints, bypassing standard authentication and control measures. SSRF enables attackers to manipulate URLs and exploit server misconfigurations to access privileged information or functionalities. This vulnerability can be exploited without user interaction, as the attacker can directly manipulate input parameters used in server-side network requests. It poses significant risks due to potential exposure of internal services or sensitive resources. The issue arises in the '/cors' endpoint, which lacks sufficient validation for incoming URLs. Attackers exploit this issue to retrieve or manipulate backend data and configurations improperly.

Technical details of this SSRF vulnerability involve the unauthorized access to the '/cors' endpoint, facilitating server requests to unintended URLs. The SSRF attack uses specific parameters within HTTP requests to target the MagicMirror application, allowing the exploitation of the internal request logic. This includes targeting localhost or internal network interfaces, often via manipulated URL query strings. Such actions can lead to requests to unauthorized locations, potentially exposing sensitive server-side configurations. Attackers often employ interactsh services to simulate these attacks and validate successful exploitation. Effective exploitation necessitates an understanding of the '/cors' logic for initiating server requests, requiring careful crafting of malicious URL parameters.

When exploited, this vulnerability may allow attackers to access sensitive information or services hosted on the internal network by leveraging the server's access capabilities. It could lead to data leaks from internal databases or expose internal network architecture by circumventing traditional network security barriers. Moreover, the possibility exists to manipulate or access cloud services through misconfigured network paths. The effects are further compounded if attackers gain the ability to alter configurations or access sensitive environments via exposed endpoints or metadata services. The exploitation's potential impact includes broader network compromise due to unauthorized data exposure and manipulation abilities.

REFERENCES

Solution Advice
  • Upgrade MagicMirror to version 2.36.0 or later.
  • Implement input validation layers to filter and validate requests appropriately.
  • Configure the server to limit the reachable URL destinations from within the '/cors' endpoint.
  • Conduct regular audits and monitoring for any irregular URL accesses or deviations from normal traffic patterns.
  • Enhance logging mechanisms on the MagicMirror server to detect and alert on potential SSRF attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.