Token Verification Vulnerability in Quiet by TryQuiet
CVE-2025-53940
8.5HIGH
What is CVE-2025-53940?
A vulnerability exists in Quiet, an alternative to traditional team communication tools like Slack and Discord, affecting versions up to 6.1.0-alpha.4. The backend/frontend communication API utilized an insecure, non-constant-time comparison function for token validation. This flaw made it susceptible to timing attacks, enabling attackers to infer token values by measuring response times. As incorrect tokens were processed faster, malicious actors could potentially guess valid tokens one character at a time. The issue was addressed and resolved in version 6.0.1 of Quiet.
Affected Version(s)
quiet < 6.0.1