← Back to CVE search

CVE-2026-13534

CherryHQ cherry-studio

Description

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack-s complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that -[m]emory is planned to be removed in v2 version.-

CVSS 5EPSS 0.199%Risk 0.51
View source
Published
2026-06-29 06:16:27
Affected versions
<=1.9.7
Type
Web application
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L