PT-2025-30706 · Quiet · Quiet
Published
2025-07-24
·
Updated
2025-07-25
·
CVE-2025-53940
CVSS v4.0
8.5
High
| Vector | AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quiet versions 6.1.0-alpha.4 and below
Description
Quiet’s API for backend/frontend communication used an insecure, not constant-time comparison function for token verification. This allowed for a potential timing attack where an attacker could attempt to guess the entire token one character at a time by observing slight differences in response times.
Recommendations
Upgrade to version 6.0.1.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quiet