OS Command Injection Vulnerability in Cherry Studio Desktop Client
CVE-2025-54074
What is CVE-2025-54074?
Cherry Studio, a desktop client supporting multiple LLM providers, is susceptible to OS Command Injection when interacting with a compromised MCP server in HTTP Streamable mode. Attackers can exploit this vulnerability by crafting a malicious MCP server, equipped with deceptive OAuth authorization endpoints, that lures users into establishing a connection. Once connected, this can result in unauthorized command execution on the victim's system, impacting data security and integrity. Users are advised to upgrade to version 1.5.2, where this issue has been resolved.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cherry-studio >= 1.2.5, < 1.5.2
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
