Back to overview

CVE-2026-13524

MEDIUM
5.6
CVSS 3.1
Description
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper authorization. The attack can be initiated remotely. The attack is considered to have high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.

Metadata

CVE ID
CVE-2026-13524
State
PUBLISHED
Assigner
VulDB
Reserved
2026-06-28 07:50 UTC
Published
2026-06-29 01:45 UTC
Last updated
2026-06-29 01:45 UTC
Primary CWE
CWE-285
Improper Authorization
Vendor / Product
CherryHQ / cherry-studio
Sources
cve.org  ·  NVD

Severity & Metrics

5.6 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Affected products (1)
VendorProductPlatformVersions
CherryHQ cherry-studio 1.9.0, 1.9.1, 1.9.2, 1.9.3 …
Weakness (CWE)
CWESourceDescription
CWE-266 cna Incorrect Privilege Assignment
CWE-285 cna Improper Authorization
CVSS scores (4)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
5.6 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.6 MEDIUM 3.0 cna CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
5.1 N/D 2.0 cna AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR
References (7)
Back to overview