Bug 2477644 (CVE-2026-42281) - CVE-2026-42281 magicmirror: MagicMirror²: Server-Side Request Forgery leading to information disclosure
Summary: CVE-2026-42281 magicmirror: MagicMirror²: Server-Side Request Forgery leading...
Keywords:
Status: NEW
Alias: CVE-2026-42281
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2477803 2477804 2477805 2477806 2477807
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-05-14 21:02 UTC by OSIDB Bzimport
Modified: 2026-05-15 08:37 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-05-14 21:02:44 UTC
MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (**VAR_NAME**), enabling exfiltration of server-side secrets. This vulnerability is fixed in 2.36.0.


Note You need to log in before you can comment on or make changes to this bug.