peter bassill · operator
$ cve CVE-2025-54382 JSON

CVE-2025-54382

9.6
CRITICAL · CVSS 3.1 · EPSS 7.4% (pctl 94)

In your normal cycle

Critical by CVSS (9.6), but no sign of active exploitation.

Description

Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when connecting to streamableHttp MCP servers. The issue arises from the server’s implicit trust in the oauth auth redirection endpoints and failure to properly sanitize the URL. This issue has been patched in version 1.5.2.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS7.35% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2025-08-13
Last modified2026-06-17

Affected (1)

VendorProduct
cherry-aicherry studio

References

→ the Explorer  ·  watch your stack  ·  NVD