Timing Attack Vulnerability in Mojic CLI Tool by Not Amit Gamer
CVE-2026-41244

4.7MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 April 2026

What is CVE-2026-41244?

Mojic, a command-line interface tool designed to transform readable C code into a chaotic stream of emojis, has a vulnerability related to its CipherEngine. Before version 2.1.4, this tool utilized a standard equality operator (!==) during the decryption phase to verify the integrity of the HMAC-SHA256 seal. This weakness resulted in an Observable Timing Discrepancy, enabling potential attackers to exploit timing attacks and bypass crucial file integrity checks. This vulnerability has been addressed in version 2.1.4, reinforcing the security of the tool.

Affected Version(s)

mojic < 2.1.4

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.