NONE · 0

CVE-2025-53940

Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's API for ba...

Vulnerability Description

Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's API for backend/frontend communication was using an insecure, not constant-time comparison function for token verification. This allowed for a potential timing attack where an attacker would try different token values and observe tiny differences in the response time (wrong characters fail faster) to guess the whole token one character at a time. This is fixed in version 6.0.1.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-53940?

CVE-2025-53940 is a documented vulnerability. Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In versions 6.1.0-alpha.4 and below, Quiet's API for ba...

How severe is CVE-2025-53940?

CVSS scoring is not yet available for CVE-2025-53940. Check NVD for updates.

Is there a patch for CVE-2025-53940?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.