Remote Code Execution Vulnerability in Cherry Studio Desktop Client
CVE-2025-54063
8HIGH
What is CVE-2025-54063?
The Cherry Studio desktop client, supporting multiple LLM providers, has a vulnerability that allows for remote code execution via custom URL handling in versions 1.4.8 to 1.5.0. This security flaw can be exploited when a user clicks on a malicious link that triggers the app’s URL handler. Consequently, this leads to unauthorized execution of code on the user's machine, exposing it to potential threats. The issue has been addressed in version 1.5.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cherry-studio >= 1.4.8, < 1.5.1
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
