CVE-2025-54063

8.0

CherryHQ · Cherry Studio

Cherry Studio versions 1.4.8 through 1.5.0 contain a remote code execution vulnerability triggered by malicious custom URL handlers.

Executive summary

Cherry Studio is affected by a critical remote code execution vulnerability that allows an unauthenticated attacker to execute arbitrary code on a victim's machine via a crafted URL.

Vulnerability

The software fails to properly sanitize input in its custom URL handler, allowing for code injection (CWE-94) when a user clicks a malicious link. The attacker does not require authentication and can trigger this flaw remotely by hosting a crafted URL on a website.

Business impact

Successful exploitation results in full remote code execution on the host machine, granting an attacker the ability to install malware, exfiltrate sensitive data, or pivot within the local network. With a CVSS score of 8.0, this vulnerability presents a significant risk to organizational endpoints, particularly for users who frequently interact with external web content.

Remediation

Immediate Action: Update Cherry Studio to version 1.5.1 or later immediately to apply the required security patches for the URL handling mechanism.

Proactive Monitoring: Review endpoint security logs for unexpected process executions or suspicious network connections originating from the Cherry Studio application.

Compensating Controls: While browser-based protections may mitigate some delivery vectors, users should exercise caution when clicking unknown links until the update is applied to all affected workstations.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of potential remote code execution, organizations should prioritize patching this vulnerability across all deployed instances of Cherry Studio. Administrators must ensure that the update to version 1.5.1 is deployed to all workstations as soon as possible to neutralize the risk of unauthorized code execution via malicious URL handling.

More CherryHQ CVEs

Sources