← Zurück zur CVE-Suche

CVE-2026-13534

CherryHQ cherry-studio

Beschreibung

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack-s complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that -[m]emory is planned to be removed in v2 version.-

CVSS 5EPSS 0.199%Risiko 0.51
Quelle öffnen
Veröffentlicht
2026-06-29 06:16:27
Betroffene Versionen
<=1.9.7
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L