๐Ÿ” CVE Alert

CVE-2026-41244

MEDIUM 4.7

Mojic: Observable Timing Discrepancy in HMAC Verification

CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th

Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack. This vulnerability is fixed in 2.1.4.

CWE CWE-208
Vendor notamitgamer
Product mojic
Published Apr 24, 2026
Last Updated Apr 24, 2026
Stay Ahead of the Next One

Get instant alerts for notamitgamer mojic

Be the first to know when new medium vulnerabilities affecting notamitgamer mojic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

notamitgamer / mojic
< 2.1.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/notamitgamer/mojic/security/advisories/GHSA-wqq3-wfmp-v85g