External risk intelligence

Cherry Studio Command Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2025-61929

The vulnerability exists in a desktop client application and requires user interaction via a custom URI scheme. It is not an internet-facing service, API, or appliance; rather, it is client-side software that requires a local user to click a link while the application is installed. There is no typical public network exposure for the application itself.

Code Injection

Cherry Ai Cherry Studio

before 1.6.4

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A desktop client application has a vulnerability that could allow a malicious website to execute commands on a user's computer if the user clicks a specially crafted link. This could lead to a compromise of the user's system.

  • Malicious links can trigger commands on your computer.
  • It’s a client-side risk requiring user interaction.
  • Confirm if this client is used within the organization.

Attack Path

How an attacker could exploit the issue

An attacker can trick a user into clicking a specially crafted link, likely presented on a website or in a message. This link exploits the Cherry Studio desktop client's handling of custom protocol URLs. When the user interacts with the link, the application parses malicious data embedded within it and directly executes commands, potentially compromising the user's system.

  • Requires a user to click a malicious link.
  • Vulnerable component handles custom protocol URLs.
  • Leads to arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

Cherry Studio, when processing specially crafted `cherrystudio://mcp` URLs, could directly execute commands embedded in base64-encoded configuration data. This could occur when a user clicks a malicious link on a website, leading to compromise when the user clicks through a seemingly normal pop-up.

  • System commands could be executed.
  • Malicious links could trigger execution.
  • User compromise could occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world remediation for this vulnerability requires identifying Cherry Studio installations and understanding their reachability and business criticality. Application owners, potentially supported by infrastructure or platform teams, should lead the effort to confirm asset ownership and then develop a risk-based remediation plan, coordinating with the vendor if necessary.

  • Application owners to manage remediation.
  • Verify user interaction exposure.
  • Plan vendor-supported updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cherry Studio?

Cherry Studio is a desktop software application designed to interface with multiple Large Language Model (LLM) providers in one place. It helps users manage and interact with various AI services directly from their local computer.

What does CWE-94 mean for CVE-2025-61929?

CWE-94 refers to Improper Control of Generation of Code, or Code Injection. In this CVE, the application takes instructions from a custom link and executes them as commands on your machine without proper verification of the content.

How is this vulnerability triggered?

The flaw is triggered when a user clicks a malicious link that uses the 'cherrystudio://' protocol. Simply viewing a webpage or receiving a link does not trigger the bug; the user must actively click the link for the application to process the harmful data.

Is my machine at risk if I use Cherry Studio?

According to Halo Surface Signal, this is client-side software, not an internet-facing service or server. While the risk is real, it depends on user interaction. You are primarily at risk if you click untrusted links while the application is installed.

What should I do to protect my system?

Identify where this application is installed in your environment and monitor for updates from the vendor. Because this relies on user interaction, advise users to be cautious about clicking unexpected links, especially those formatted to open local applications.

References