Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-13524: Improper authorization in Cherry Studio MCP OAuth callback server

A vulnerability in CherryHQ cherry-studio up to version 1.9.6 affects the MCP OAuth Local Callback Server (src/main/services/mcp/oauth/callback.ts), where manipulation of the 'code' argument leads to improper authorization and can be triggered remotely. The exploit has been publicly disclosed and a fix pull request is still awaiting acceptance.

Disclosed 29 June 2026 · Record updated 13 September 2026

Impact

Remote attackers could exploit improper authorization in the MCP OAuth local callback handling, though the attack is described as high complexity and difficult to exploit.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-13524