PatchSiren cyber security CVE debrief
CVE-2026-13534 CherryHQ CVE debrief
CVE-2026-13534 is an authorization bypass vulnerability in CherryHQ cherry-studio up to 1.9.7. The vulnerability affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. An attacker can manipulate the argument state to bypass authorization. The attack can be initiated remotely, but its complexity is rated as high and exploitability is difficult. The exploit is now public and may be used. The vendor plans to remove the affected memory in version 2.
- Vendor
- CherryHQ
- Product
- cherry-studio
- CVSS
- LOW 1.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-29
- Original CVE updated
- 2026-06-29
- Advisory published
- 2026-06-29
- Advisory updated
- 2026-06-29
Who should care
Security teams responsible for CherryHQ cherry-studio up to 1.9.7 should be aware of this vulnerability. Due to the high complexity and difficult exploitability, defenders should prioritize patching and monitoring for potential exploitation attempts. Organizations using the affected version should assess their exposure and take necessary actions.
Technical summary
CVE-2026-13534 is an authorization bypass vulnerability in the CherryHQ cherry-studio up to 1.9.7. The vulnerability is located in the sha256 function of the MemoryService.ts file in the CherryIN Preload API component. An attacker can manipulate the state argument to bypass authorization. The CVSS score is 1.3, indicating a low severity. The attack vector is network-based, and the attack complexity is high.
Defensive priority
Defenders should prioritize patching the vulnerability and monitoring for potential exploitation attempts. Due to the high complexity and difficult exploitability, defenders may also consider compensating controls and exception tracking.
Recommended defensive actions
- Apply the vendor's planned patch in version 2.
- Monitor for potential exploitation attempts.
- Perform a thorough inventory check to identify affected systems.
- Implement compensating controls to mitigate potential exploitation.
- Track exceptions and anomalies in system behavior.
Evidence notes
The CVE-2026-13534 vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. The vulnerability affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. The attack can be initiated remotely, but its complexity is rated as high and exploitability is difficult. The exploit is now public and may be used.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-13534 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-13534
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-13534 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-13534
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/CherryHQ/cherry-studio/
-
Source reference
Unverified legacy reference
URL: https://github.com/CherryHQ/cherry-studio/issues/15411
-
Source reference
Unverified legacy reference
URL: https://github.com/CherryHQ/cherry-studio/pull/15413
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-13534
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/841998
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/374542
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/374542/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.