Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 29 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Jun 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version." | |
| Title | CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization | |
| First Time appeared |
Cherryhq
Cherryhq cherry-studio |
|
| Weaknesses | CWE-285 CWE-639 |
|
| CPEs | cpe:2.3:a:cherryhq:cherry-studio:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cherryhq
Cherryhq cherry-studio |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-29T13:37:35.608Z
Reserved: 2026-06-28T09:26:12.051Z
Link: CVE-2026-13534
Updated: 2026-06-29T13:37:30.159Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-29T09:15:03Z