CVE-2026-40501
HIGHCherry Studio RCE via SearchService nodeIntegration Misconfiguration
Title source: cnaDescription
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code execution vulnerability in SearchService that allows remote attackers to execute arbitrary code by delivering malicious JavaScript through controlled search provider content loaded into an Electron BrowserWindow configured with nodeIntegration enabled and contextIsolation disabled. Attackers who control a search engine provider, individual search result pages, or provider settings pages can execute JavaScript with full Node.js privileges, gaining access to fs, child_process, os, and process.env under the operating-system account of the Cherry Studio process.
References (3)
Core 3
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://gist.github.com/Mundi-Xu/99af1b08275fd437cfb79bfe481e68b7
Patch patch
Patch Commit
https://github.com/CherryHQ/cherry-studio/commit/151853035e8e417a51559ebfc243eda98361a882
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/cherry-studio-rce-via-searchservice-nodeintegration-misconfiguration
Scores
CVSS v3
8.8
EPSS
0.0044
EPSS Percentile
36.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-829
Status
published
Products (2)
CherryHQ/cherry-studio
1.2.2 - 1.9.12
CherryHQ/cherry-studio
f9c6bddae5b91cc50872c76e791105fa219d0d34 - 151853035e8e417a51559ebfc243eda98361a882
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026