Vulnerabilities/

MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint

Severity:
High

Description

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services.

Recommendation

Update the magicmirror package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
magicmirror
Anything's wrong? Let us know Last updated on May 14, 2026