{"id":"CVE-2026-41244","aliases":["GHSA-wqq3-wfmp-v85g"],"url":"https://o3.security/vulnerability/CVE-2026-41244","summary":"Mojic: Observable Timing Discrepancy in HMAC Verification","details":"Mojic is a CLI tool to transform readable C code into an unrecognizable chaotic stream of emojis. Prior to 2.1.4, the CipherEngine uses a standard equality operator (!==) to verify the HMAC-SHA256 integrity seal during the decryption phase. This creates an Observable Timing Discrepancy (CWE-208), allowing a potential attacker to bypass the file integrity check via a timing attack. This vulnerability is fixed in 2.1.4.","published":"2026-04-24T19:11:54.892Z","modified":"2026-08-07T11:31:18.327544831Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"mojic","fixedVersion":"2.1.4"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41244.json"},{"type":"ADVISORY","url":"https://github.com/notamitgamer/mojic/security/advisories/GHSA-wqq3-wfmp-v85g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41244"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:18.327544831Z"}}