CVE-2025-54382

CRITICAL

Cherry Studio < 1.5.2 - Remote Code Execution via OAuth Redirect URL

Title source: llm
STIX 2.1

Description

Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’s implicit trust in the oauth auth redirection endpoints and failure to properly sanitize the URL. This issue has been patched in version 1.5.2.

References (1)

Core 1
Core References

Scores

CVSS v3 9.6
EPSS 0.0545
EPSS Percentile 91.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
cherry-ai/cherry_studio < 1.5.2
Published Aug 13, 2025
Tracked Since Feb 18, 2026