PT-2026-5304 · Unknown+1 · Libparsec Crypto+1

Published

2026-01-29

·

Updated

2026-03-02

·

CVE-2025-62514

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Parsec versions prior to 3.6.0
Description Parsec is a cloud-based application for cryptographically secure file sharing. In versions on the 3.x branch prior to 3.6.0, the libparsec crypto component does not check for weak order points of Curve25519 when compiled with its RustCrypto backend. This allows an attacker in a man-in-the-middle position to provide weak order points to both parties during the Diffie-Hellman exchange. This can result in both parties obtaining the same shared key, enabling a successful SAS code exchange and misleading both parties into believing no MITM attack has occurred. Only Parsec web is impacted. The vulnerable component is libparsec crypto.
Recommendations Update to Parsec version 3.6.0 or later.

Exploit

Fix

Use of a Broken Cryptographic Algorithm

Weakness Enumeration

Related Identifiers

CVE-2025-62514
GHSA-HRC9-GM58-PGJ9

Affected Products

Parsec
Libparsec Crypto