Back to CVE List

CVE-2026-13534

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.0 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Vulnerability Description

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version."

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-285
Source
NVD
Vendor
CherryHQ
Product
cherry-studio

External References

Discussion (0)

Add Comment

No comments yet. Be the first!