Executive brief
Mousehole is a background service that automatically updates a seedbox's IP address and provides a web interface for management. Prior to version 0.4.05, the service's management interface is completely open to anyone who can reach it on the network, allowing unauthorized users to read, replace, or misuse stored credentials used to access a file-sharing service. Since many deployments publish the service port broadly, this can expose credentials on shared networks or VPNs.
Technical details
Mousehole's HTTP/WebSocket management interface lacks application-layer authentication, CSRF protection, and proper origin validation, making all endpoints (GET /state, PUT /state, POST /update, and WebSocket /web/ws) accessible to any network-reachable client. The vulnerability stems from storing and reusing a MyAnonamouse (MAM) session cookie in serialized state responses and WebSocket broadcasts without restricting access. An attacker can read the cookie via GET /state, monitor future state updates via WebSocket connections, replace the stored cookie via PUT /state, or trigger MAM update side effects via POST /update. The typical Docker deployment syntax (5010:5010) binds the port to all interfaces, making the issue reachable from mixed-trust LAN/VPN networks. Version 0.4.05 and later patch this issue by separating internal and public serialization and adding authentication mechanisms.
Affected products
- t-mart Mousehole prior to 0.4.05
Timeline
- 2026-09-11: disclosed
- 2026: patched: Version 0.4.05 patches the issue