A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version."
Metrics
Affected Vendors & Products
References
History
Mon, 29 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version." | |
| Title | CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization | |
| First Time appeared |
Cherryhq
Cherryhq cherry-studio |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:cherryhq:cherry-studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cherryhq
Cherryhq cherry-studio |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-29T04:15:09.623Z
Reserved: 2026-06-28T09:26:12.051Z
Link: CVE-2026-13534
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T09:15:03Z