We found results for “”
CVE-2025-61929
Good to know:
Date: October 10, 2025
Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called "cherrystudio://". When handling the MCP installation URL, it parses the base64-encoded configuration data and directly executes the command within it. In the files "src/main/services/ProtocolClient.ts" and "src/main/services/urlschema/mcp-install.ts", when receiving a URL of the "cherrystudio://mcp" type, the "handleMcpProtocolUrl" function is called for processing. If an attacker crafts malicious content and posts it on a website or elsewhere (there are many exploitation methods, such as creating a malicious website with a button containing this malicious content), when the user clicks it, since the pop-up window contains normal content, the direct click is considered a scene action, and the malicious command is directly triggered, leading to the user being compromised. As of time of publication, no known patched versions exist.
Severity Score
Severity Score
Weakness Type (CWE)
Improper Control of Generation of Code ('Code Injection')
CWE-94Top Fix
Upgrade Version
Upgrade to version https://github.com/CherryHQ/cherry-studio.git - v1.6.4
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | REQUIRED |
| Scope (S): | CHANGED |
| Confidentiality (C): | HIGH |
| Integrity (I): | HIGH |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


