Unrated severityNVD Advisory· Published Aug 13, 2025· Updated Aug 13, 2025
Cherry Studio RCE Vulnerability Disclosure
CVE-2025-54382
Description
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’s implicit trust in the oauth auth redirection endpoints and failure to properly sanitize the URL. This issue has been patched in version 1.5.2.
Affected products
2- Range: = 1.5.1
- CherryHQ/cherry-studiov5Range: = 1.5.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/CherryHQ/cherry-studio/security/advisories/GHSA-gjp6-9cvg-8w93mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.