PT-2025-30706 · Quiet · Quiet

Published

2025-07-24

·

Updated

2025-07-25

·

CVE-2025-53940

CVSS v4.0

8.5

High

VectorAV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quiet versions 6.1.0-alpha.4 and below
Description Quiet’s API for backend/frontend communication used an insecure, not constant-time comparison function for token verification. This allowed for a potential timing attack where an attacker could attempt to guess the entire token one character at a time by observing slight differences in response times.
Recommendations Upgrade to version 6.0.1.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-53940
GHSA-GPW8-W78H-XJ67

Affected Products

Quiet