Popis
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack-s complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that -[m]emory is planned to be removed in v2 version.-
CVSS 5EPSS 0.199%Riziko 0.51
Zobraziť zdroj- Zverejnené
- 2026-06-29 06:16:27
- Dotknuté verzie
- <=1.9.7
- Typ
- Webová aplikácia
- Vektor
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L