Weak Order Point Vulnerability in Parsec Cloud Application by Scille
CVE-2025-62514

8.3HIGH

Key Information:

Vendor

Scille

Vendor
CVE Published:
29 January 2026

What is CVE-2025-62514?

The Parsec cloud application has a vulnerability stemming from the libparsec_crypto component, found in versions prior to 3.6.0. This issue is related to the weak order point of Curve25519, exploited by an attacker positioned as a man-in-the-middle. In this scenario, the attacker can present weak order points during the Diffie-Hellman exchange, which significantly increases the chances of both parties arriving at the same shared key. This deception misleads participants into believing their connection is secure, even when it is not. Notably, only the Parsec web application is impacted, as the desktop version utilizes a different backend (libsodium) which is not affected. The vulnerability has been patched in version 3.6.0 of Parsec.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

parsec-cloud >= 3.0.0-alpha, < 3.6.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.