Cherry Ai has a narrow vulnerability footprint centered on its Cherry Studio product, a desktop application for AI model interaction and management. The observed exposures reflect the application-layer context rather than a structural pattern; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cherry Ai over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54063CRITICAL Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custo | Aug 11, 2025 | 9.6 | 33 | NO | NO |
CVE-2025-61929CRITICAL Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation U | Oct 10, 2025 | 9.6 | 32 | NO | NO |
CVE-2025-54074CRITICAL Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio is vulnerable to OS Command Injection during a connection wi | Aug 13, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-54382HIGH Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (RCE) vulnerability exists in the Cherry Studio platform when | Aug 13, 2025 | 8.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cherry Ai.
Media articles that mention a CVE ID that affects a product developed by Cherry Ai — matched by CVE ID, not by vendor name.