Vulnerability  ·  2026-06-30

CherryStudio MCP OAuth Local Callback Server — Authorization Bypass via Code Parameter Manipulation

VulnerabilityMedium impactGlobalCVE-2026-13524
CherryHQ cherry-studio up to version 1.9.6 contains an improper authorization vulnerability in the MCP OAuth local callback server (src/main/services/mcp/oauth/callback.ts). Manipulation of the 'code' argument in the OAuth callback flow allows a remote attacker to bypass authorization controls, potentially hijacking MCP OAuth sessions or intercepting authorization codes.
Cherry Studio is a desktop AI client that connects to MCP servers using OAuth. An authorization bypass in the OAuth callback allows an attacker to hijack the OAuth flow and obtain tokens for MCP servers that Cherry Studio is authenticated to — granting attacker access to all tools and data sources the victim's MCP integrations can reach.
Remote attacker manipulates the OAuth callback 'code' parameter in the MCP OAuth local callback server to bypass authorization checks and hijack or forge an OAuth session.
CherryHQ/cherry-studio ≤ 1.9.6
Upgrade to CherryHQ/cherry-studio > 1.9.6. See: https://github.com/CherryHQ/cherry-studio/
Sources
NVD CVE-2026-13524CherryHQ/cherry-studio GitHub
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →