All 7 CVE vulnerabilities found in cherry-studio, with AI-generated Chinese analysis, references, and POCs.
Vendor: CherryHQ
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-40501 | Cherry Studio RCE via SearchService nodeIntegration Misconfiguration CWE-829 | 8.8 | High | 2026-07-15 |
| CVE-2026-13534 | CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization CWE-639 | 5.0 | Medium | 2026-06-29 |
| CVE-2026-13524 | CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization CWE-285 | 5.6 | Medium | 2026-06-29 |
| CVE-2025-61929 | Cherry Studio allows one-click on a specific URL to cause a command to execute CWE-94 | 9.7 | Critical | 2025-10-10 |
| CVE-2025-54382 | Cherry Studio RCE Vulnerability Disclosure CWE-78 | 9.7 | Critical | 2025-08-13 |
| CVE-2025-54074 | Cherry Studio is Vulnerable to OS Command Injection during Connection with a Malicious MCP Server CWE-78 | 8.8AI | High AI | 2025-08-13 |
| CVE-2025-54063 | Cherry Studio One-click Remote Code Execution Vulnerability through Custom URL Handling CWE-94 | 8.0 | High | 2025-08-11 |
All 7 known CVE vulnerabilities affecting cherry-studio with full Chinese analysis, references, and POCs where available.