CVE-2026-13534 is an authorization bypass vulnerability in CherryHQ cherry-studio up to 1.9.7. The vulnerability affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. An attacker can manipulate the argument state to bypass authorization. The attack can be initiated remotely, but its complexity is rated as high and exploitability is difficu [truncated]
CVE-2026-13524 is a security vulnerability detected in CherryHQ cherry-studio up to 1.9.6. The vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper authorization. The attack can be initiated remotely and is considered to have high complexity with difficult exploitabil [truncated]