A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-61929, has been discovered in Cherry Studio, a desktop client supporting multiple large language model (LLM) providers. The flaw, rated with a CVSS score of 9.7, allows attackers to execute arbitrary commands on a victim's system through a specially crafted custom URL protocol. Cherry Studio registers a custom protocol handler, 'cherrystudio://', which is intended to facilitate legitimate operations such as MCP installation. However, the vulnerability arises from the way the application parses base64-encoded configuration data embedded in the URL. When a user clicks on a maliciously crafted 'cherrystudio://mcp' link, the application directly executes the command contained within the URL without adequate validation or user confirmation. This makes it possible for attackers to exploit the flaw by luring users to click on a link embedded in a website, email, or other digital content. The attack is particularly dangerous because the pop-up window generated by the application appears normal, increasing the likelihood that users will trust and interact with it. Once the link is clicked, the malicious command is executed in the context of the user's system, potentially leading to full compromise. As of the time of disclosure, there are no known patched versions available to address this vulnerability, leaving all current installations of Cherry Studio exposed. Security researchers have highlighted the ease of exploitation, noting that the attack can be triggered with a single click, requiring minimal user interaction. The vulnerability affects all versions of Cherry Studio that register and process the custom protocol as described. The issue was reported to security-advisories@github.com and has been publicly documented in security advisories and vulnerability databases. Organizations and individuals using Cherry Studio are urged to exercise extreme caution and avoid clicking on untrusted links until a patch is released. The lack of a fix increases the urgency for users to implement temporary mitigations, such as disabling the custom protocol handler if possible. The vulnerability underscores the risks associated with custom URL protocols in desktop applications, especially when input validation is insufficient. Security teams are advised to monitor for exploitation attempts and consider network or endpoint controls to block malicious protocol invocations. The incident has drawn attention to the broader need for secure handling of custom protocols in software that interfaces with external content.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A critical vulnerability, CVE-2025-61929, was disclosed for Cherry Studio. The flaw was described as allowing one-click remote code execution via a custom URL protocol and assigned a CVSS score of 9.7.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.