Impact
Mousehole exposes an unauthenticated HTTP/WebSocket boundary that allows any client that can reach the published port to read, modify, or replace the MyAnonamouse (MAM) session cookie. This capability enables attackers to impersonate users, trigger unwanted MAM update side effects, and gain access to the service’s public API responses and internal state, effectively bypassing authentication and leaking sensitive browser session data.
Affected Systems
The vulnerable component is the Mousehole background service provided by t‑mart. Versions prior to 0.4.0 are affected by the unauthenticated HTTP/WebSocket boundary; the issue is fixed in 0.4.0 and later releases.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is considered moderate. The EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based; any host that can connect to Mousehole’s default port 5010—whether on a local or external network if the port is published—can exploit the flaw without credentials. Successful exploitation could lead to data theft, session hijacking, and unauthorized state changes within the application.
OpenCVE Enrichment