FixVibe

// 探测 / 聚焦

MagicMirror /cors SSRF Exposure

A smart-mirror helper endpoint should not become a network proxy.

概要

MagicMirror is often deployed on small always-on devices, home labs, and dashboards that sit closer to internal networks than a normal public web app. CVE-2026-42281 turns an unauthenticated helper endpoint into a server-side fetch path, so an exposed instance can become a proxy from the attacker to places the attacker cannot reach directly.

工作原理

MagicMirror deployments affected by CVE-2026-42281 can expose an unauthenticated server-side URL fetch path through the `/cors` endpoint. The risk is SSRF into destinations reachable from the MagicMirror host.

影响范围

A confirmed exposure means the MagicMirror server accepted an unauthenticated URL fetch request. In real deployments, that can put internal services, metadata endpoints, and server-side secrets near the blast radius, depending on where the mirror is hosted and what network routes it can reach.

// what fixvibe checks

What FixVibe checks

FixVibe checks this class with verified-domain active testing that is bounded, non-destructive, and evidence-driven. Public reports describe the affected surface and remediation. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

铁壁防御

Upgrade MagicMirror to 2.36.0 or newer and restart the service that actually serves traffic. Until the fixed runtime is live, keep the MagicMirror HTTP interface behind trusted-network, VPN, SSO, or authenticated reverse-proxy controls, and block unauthenticated `/cors` access at the edge.

// 在你自己的应用上跑一遍

放心继续发布,FixVibe 持续帮你看守风险。

FixVibe 像攻击者一样对你的应用公开面进行压力测试 —— 无代理、无安装、无信用卡。我们持续研究新的漏洞模式,并把它们转化成实用检查和可直接用于 Cursor、Claude、Copilot 的修复方案。

主动探测
108
本类别中触发的测试
模块
30
专属 主动探测 检查
每次扫描
397+
跨所有类别的测试
  • 免费 —— 无需信用卡,无需安装,无需 Slack 通知
  • 只需粘贴 URL —— 我们爬取、探测、生成报告
  • 按严重程度分级,去重至只剩信号
  • 最新 AI 修复提示词,可直接粘贴到 Cursor、Claude、Copilot
运行免费扫描

// 最新检查 · 实用修复 · 安心发布

MagicMirror /cors SSRF Exposure — 漏洞聚焦 | FixVibe · FixVibe