CVE-2025-54074

Source
https://cve.org/CVERecord?id=CVE-2025-54074
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54074.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-54074
Aliases
  • GHSA-8xr5-732g-84px
Published
2025-08-13T13:27:28.232Z
Modified
2026-04-10T05:32:21.771725Z
Severity
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Cherry Studio is Vulnerable to OS Command Injection during Connection with a Malicious MCP Server
Details

Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection during a connection with a malicious MCP server in HTTP Streamable mode. Attackers can setup a malicious MCP server with compatible OAuth authorization server endpoints and trick victims into connecting it, leading to OS command injection in vulnerable clients. This issue has been patched in version 1.5.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-78"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/54xxx/CVE-2025-54074.json"
}
References

Affected packages

Git / github.com/cherryhq/cherry-studio

Affected ranges

Type
GIT
Repo
https://github.com/cherryhq/cherry-studio
Events

Affected versions

v1.*
v1.2.10
v1.2.5
v1.2.6
v1.2.7
v1.2.8
v1.2.9
v1.3.0
v1.3.1
v1.3.10
v1.3.11
v1.3.12
v1.3.2
v1.3.3
v1.3.4
v1.3.5
v1.3.6
v1.3.7
v1.3.8
v1.3.9
v1.4.0
v1.4.0-rc.1
v1.4.0-rc.2
v1.4.0-rc.3
v1.4.1
v1.4.10
v1.4.11
v1.4.2
v1.4.2-ui-preview
v1.4.4
v1.4.5
v1.4.6
v1.4.7
v1.4.8
v1.4.9
v1.5.0
v1.5.0-rc.1
v1.5.0-rc.3
v1.5.0-rc.4
v1.5.0-rc.5
v1.5.0-rc.6
v1.5.0-rc.7
v1.5.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-54074.json"