Critical severity9.6NVD Advisory· Published Aug 13, 2025· Updated Jun 17, 2026
CVE-2025-54382
CVE-2025-54382
Description
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’s implicit trust in the oauth auth redirection endpoints and failure to properly sanitize the URL. This issue has been patched in version 1.5.2.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <=1.5.1
- Range: = 1.5.1
Patches
Vulnerability mechanics
References
1- github.com/CherryHQ/cherry-studio/security/advisories/GHSA-gjp6-9cvg-8w93nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.