Description
Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN provenance checks. The service stores a MyAnonamouse (MAM) session cookie in state and reuses the same cookie-bearing serialization for persisted state, public API responses, and WebSocket state updates. Any client that can reach the published Mousehole port can read cookie-bearing state, connect to WebSocket state updates, replace the stored cookie, or force MAM update side effects. The deployment examples publish port 5010 broadly with Docker's `5010:5010` syntax, which can make the issue reachable on mixed-trust LAN/VPN interfaces. Version 0.4.0 patches the issue.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass and sensitive data disclosure
Action: Immediate Patch
AI Analysis

Impact

Mousehole exposes an unauthenticated HTTP/WebSocket boundary that allows any client that can reach the published port to read, modify, or replace the MyAnonamouse (MAM) session cookie. This capability enables attackers to impersonate users, trigger unwanted MAM update side effects, and gain access to the service’s public API responses and internal state, effectively bypassing authentication and leaking sensitive browser session data.

Affected Systems

The vulnerable component is the Mousehole background service provided by t‑mart. Versions prior to 0.4.0 are affected by the unauthenticated HTTP/WebSocket boundary; the issue is fixed in 0.4.0 and later releases.

Risk and Exploitability

With a CVSS score of 6.9 the vulnerability is considered moderate. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based; any host that can connect to Mousehole’s default port 5010—whether on a local or external network if the port is published—can exploit the flaw without credentials. Successful exploitation could lead to data theft, session hijacking, and unauthorized state changes within the application.

Generated by OpenCVE AI on September 15, 2026 at 19:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Mousehole 0.4.0 or later, which removes the exposed unauthenticated boundary.
  • Limit access to the service’s default port (5010) by configuring Docker or firewall rules to bind only to trusted LAN interfaces or localhost.
  • If an upgrade is delayed, enforce a proxy or authentication layer that requires credentials before allowing connections to the service port.

Generated by OpenCVE AI on September 15, 2026 at 19:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared T-mart
T-mart mousehole
Vendors & Products T-mart
T-mart mousehole

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN provenance checks. The service stores a MyAnonamouse (MAM) session cookie in state and reuses the same cookie-bearing serialization for persisted state, public API responses, and WebSocket state updates. Any client that can reach the published Mousehole port can read cookie-bearing state, connect to WebSocket state updates, replace the stored cookie, or force MAM update side effects. The deployment examples publish port 5010 broadly with Docker's `5010:5010` syntax, which can make the issue reachable on mixed-trust LAN/VPN interfaces. Version 0.4.0 patches the issue.
Title Mousehole: Unauthenticated HTTP/WebSocket boundary exposes and mutates MAM cookie state
Weaknesses CWE-200
CWE-306
CWE-346
CWE-352
CWE-862
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

T-mart Mousehole
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T20:00:04.091Z

Reserved: 2026-06-02T22:46:02.580Z

Link: CVE-2026-50025

cve-icon Vulnrichment

Updated: 2026-09-14T19:59:58.447Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:10.933

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-50025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:00:08Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-346

    Origin Validation Error

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization