Token Verification Vulnerability in Quiet by TryQuiet
CVE-2025-53940

8.5HIGH

Key Information:

Vendor

Tryquiet

Status
Vendor
CVE Published:
24 July 2025

What is CVE-2025-53940?

A vulnerability exists in Quiet, an alternative to traditional team communication tools like Slack and Discord, affecting versions up to 6.1.0-alpha.4. The backend/frontend communication API utilized an insecure, non-constant-time comparison function for token validation. This flaw made it susceptible to timing attacks, enabling attackers to infer token values by measuring response times. As incorrect tokens were processed faster, malicious actors could potentially guess valid tokens one character at a time. The issue was addressed and resolved in version 6.0.1 of Quiet.

Affected Version(s)

quiet < 6.0.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53940 : Token Verification Vulnerability in Quiet by TryQuiet