PatchSiren

CherryHQ CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW CherryHQ CVE published 2026-06-29

CVE-2026-13534

CVE-2026-13534 is an authorization bypass vulnerability in CherryHQ cherry-studio up to 1.9.7. The vulnerability affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. An attacker can manipulate the argument state to bypass authorization. The attack can be initiated remotely, but its complexity is rated as high and exploitability is difficu [truncated]

LOW CherryHQ CVE published 2026-06-29

CVE-2026-13524

CVE-2026-13524 is a security vulnerability detected in CherryHQ cherry-studio up to 1.9.6. The vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper authorization. The attack can be initiated remotely and is considered to have high complexity with difficult exploitabil [truncated]