---
id: CVE-2026-13534
title: A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7
summary: >-
  A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This
  affects the function sha256 of the file
  src/main/services/memory/MemoryService.ts of the component CherryIN Preload
  API. Performing a manipulation of the argument s…
severity: medium
cvss: 5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-285
  - CWE-639
published: '2026-06-29'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13534'
references:
  - url: 'https://github.com/CherryHQ/cherry-studio/'
    label: cna@vuldb.com
  - url: 'https://github.com/CherryHQ/cherry-studio/issues/15411'
    label: cna@vuldb.com
  - url: 'https://github.com/CherryHQ/cherry-studio/pull/15413'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-13534'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/841998'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374542'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/374542/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-06-29T13:42:12.348Z'
epss: 0.00325
epssPercentile: 0.22898
---

## Overview

A vulnerability was detected in CherryHQ cherry-studio up to 1.9.7. This affects the function sha256 of the file src/main/services/memory/MemoryService.ts of the component CherryIN Preload API. Performing a manipulation of the argument state results in authorization bypass. The attack can be initiated remotely. The attack's complexity is rated as high. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The vendor explains, that "[m]emory is planned to be removed in v2 version."

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
