CVE-2025-61929: Cherry Studio allows one-click on a specific URL to cause a command to execute

Published Oct 10, 2025
·
Updated

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called cherrystudio://. When handling the MCP installation URL, it parses the base64-encoded configuration data and directly executes the command within it. In the files src/main/services/ProtocolClient.ts and src/main/services/urlschema/mcp-install.ts, when receiving a URL of the cherrystudio://mcp type, the handleMcpProtocolUrl function is called for processing. If an attacker crafts malicious content and posts it on a website or elsewhere (there are many exploitation methods, such as creating a malicious website with a button containing this malicious content), when the user clicks it, since the pop-up window contains normal content, the direct click is considered a scene action, and the malicious command is directly triggered, leading to the user being compromised. As of time of publication, no known patched versions exist.

Affected Software

2 affected components
Cherry Studio Cherry Studio
Cherry-ai Cherry Studio<1.6.4

Event History

Oct 10, 2025
CVE Published
via MITRE·07:50 PM
Data Sourced
via MITRE·07:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-61929?

CVE-2025-61929 is classified as a high severity vulnerability due to its potential to execute arbitrary commands.

2

How do I fix CVE-2025-61929?

To fix CVE-2025-61929, update to the latest version of Cherry Studio where the vulnerability has been addressed.

3

What type of vulnerability is CVE-2025-61929?

CVE-2025-61929 is a command injection vulnerability related to the processing of base64-encoded configuration data.

4

What software is affected by CVE-2025-61929?

CVE-2025-61929 affects the Cherry Studio desktop client.

5

Is CVE-2025-61929 being actively exploited?

As of now, there have been no reports indicating that CVE-2025-61929 is actively being exploited in the wild.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203