PT-2026-90501 · Git+1 · Mousehole

CVE-2026-50025

·

Published

2026-09-11

·

Updated

2026-09-12

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN provenance checks. The service stores a MyAnonamouse (MAM) session cookie in state and reuses the same cookie-bearing serialization for persisted state, public API responses, and WebSocket state updates. Any client that can reach the published Mousehole port can read cookie-bearing state, connect to WebSocket state updates, replace the stored cookie, or force MAM update side effects. The deployment examples publish port 5010 broadly with Docker's 5010:5010 syntax, which can make the issue reachable on mixed-trust LAN/VPN interfaces. Version 0.4.0 patches the issue.

Exploit

Fix

Origin Validation Error

CSRF

Information Disclosure

Missing Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-50025
GHSA-V64R-GFRC-F6VQ

Affected Products

Mousehole