CVE 8 HIGH

Cherry Studio One-click Remote Code Execution Vulnerability through Custom URL Handling_CVE-2025-54063

8 / 10
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit this by hosting a malicious website or embedding a specially crafted URL on any website. If a victim clicks the exploit link in their browser, the appโ€™s custom URL handler is triggered, leading to remote code execution on the victimโ€™s machine. This issue has been patched in version 1.5.1.

Basic Information

ID CVE-2025-54063
Source GitHub_M
Published Aug 11, 2025 at 17:59
Modified Aug 11, 2025 at 18:15

Affected Product

Vendor CherryHQ
Product cherry-studio
Version >= 1.4.8, < 1.5.1
Affected Versions CherryHQ cherry-studio >= 1.4.8, < 1.5.1

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.