CVE-2026-13534

MEDIUM

CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization

Title source: cna
STIX 2.1

Description

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version."

References (7)

Core 7
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-374542 | CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization
https://vuldb.com/vuln/374542
Signature, Permissions Required signature permissions-required
VDB-374542 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/374542/cti
Third Party Advisory third-party-advisory
CVE-2026-13534 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-13534
Third Party Advisory third-party-advisory
Submit #841998 | CherryHQ cherry-studio 1.9.6 Authorization Bypass / Flow-Key Confusion
https://vuldb.com/submit/841998

Scores

CVSS v3 5.0
EPSS 0.0020
EPSS Percentile 10.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-285 CWE-639
Status published
Products (8)
CherryHQ/cherry-studio 1.9.0
CherryHQ/cherry-studio 1.9.1
CherryHQ/cherry-studio 1.9.2
CherryHQ/cherry-studio 1.9.3
CherryHQ/cherry-studio 1.9.4
CherryHQ/cherry-studio 1.9.5
CherryHQ/cherry-studio 1.9.6
CherryHQ/cherry-studio 1.9.7
Published Jun 29, 2026
Tracked Since Jun 29, 2026