CVE-2026-13524Medium· 5.6▾ SunlitA security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulat…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 30.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
0.3% → 0.4%
A security vulnerability has been detected in CherryHQ cherry-studio up to 1.9.6. This vulnerability affects unknown code of the file src/main/services/mcp/oauth/callback.ts of the component MCP OAuth Local Callback Server. The manipulation of the argument code leads to improper authorization. The attack can be initiated remotely. The attack is considered to have high complexity. It is stated that the exploitability is difficult. The exploit has been disclosed publicly and may be used. The pull request to fix this issue awaits acceptance.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96881Medium· 5.3A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1
CVE-2026-96882Medium· 5.3A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1
CVE-2026-96880Medium· 5.3A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1
CVE-2026-96556High· 7.3A flaw has been found in Neethuharii CafeManagement
CVE-2026-93961Medium· 5.3A security flaw has been discovered in Dromara UJCMS up to 12.3.1
CVE-2026-2015Medium· 6.3A weakness has been identified in Portabilis i-Educar up to 2.10