« Back to list

Cherry-ai

Cherry-ai Cherry Studio: vulnerabilities and CVEs

Cherry-ai Cherry Studio has 5 published vulnerabilities, 2 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months2
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-40501High (8.6)0.80%—Jul 15, 2026
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in SearchService that allows remote attackers to execute arbitrary code by delivering malicious…
CVE-2025-61929Critical (9.6)0.47%—Oct 10, 2025
Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation URL, it parses the base64-encoded…
CVE-2025-54382High (8.8)7.4%—Aug 13, 2025
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP…
CVE-2025-54074High (7.7)2.1%—Aug 13, 2025
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection during a connection with a malicious MCP server in HTTP…
CVE-2025-54063Critical (9.6)0.76%—Aug 11, 2025
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter5
  2. T1203 Exploitation for Client Execution5

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.