Timing Attack Vulnerability in Mojic CLI Tool by Not Amit Gamer
CVE-2026-41244
4.7MEDIUM
What is CVE-2026-41244?
Mojic, a command-line interface tool designed to transform readable C code into a chaotic stream of emojis, has a vulnerability related to its CipherEngine. Before version 2.1.4, this tool utilized a standard equality operator (!==) during the decryption phase to verify the integrity of the HMAC-SHA256 seal. This weakness resulted in an Observable Timing Discrepancy, enabling potential attackers to exploit timing attacks and bypass crucial file integrity checks. This vulnerability has been addressed in version 2.1.4, reinforcing the security of the tool.
Affected Version(s)
mojic < 2.1.4
