CVE-2026-13534
MEDIUMCherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
Title source: cnaDescription
A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version."
References (7)
Core 7
Core References
Exploit exploit
issue-tracking
https://github.com/CherryHQ/cherry-studio/issues/15411
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-374542 | CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
https://vuldb.com/vuln/374542
Signature, Permissions Required signature
permissions-required
VDB-374542 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/374542/cti
Third Party Advisory third-party-advisory
CVE-2026-13534 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-13534
Third Party Advisory third-party-advisory
Submit #841998 | CherryHQ cherry-studio 1.9.6 Authorization Bypass / Flow-Key Confusion
https://vuldb.com/submit/841998
Patch issue-tracking
patch
https://github.com/CherryHQ/cherry-studio/pull/15413
Product product
https://github.com/CherryHQ/cherry-studio/
Scores
CVSS v3
5.0
EPSS
0.0020
EPSS Percentile
10.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-285
CWE-639
Status
published
Products (8)
CherryHQ/cherry-studio
1.9.0
CherryHQ/cherry-studio
1.9.1
CherryHQ/cherry-studio
1.9.2
CherryHQ/cherry-studio
1.9.3
CherryHQ/cherry-studio
1.9.4
CherryHQ/cherry-studio
1.9.5
CherryHQ/cherry-studio
1.9.6
CherryHQ/cherry-studio
1.9.7
Published
Jun 29, 2026
Tracked Since
Jun 29, 2026