CVE-2025-13712
7.8Tencent · HunyuanDiT
A deserialization of untrusted data vulnerability in the Tencent HunyuanDiT merge endpoint allows remote attackers to execute arbitrary code with root privileges.
Executive summary
A critical remote code execution vulnerability exists in Tencent HunyuanDiT that allows unauthenticated attackers to gain root-level access via malicious file or page interaction.
Vulnerability
The flaw resides within the merge endpoint, which fails to properly validate user-supplied data, leading to the deserialization of untrusted input. An attacker can exploit this via user interaction, such as forcing a target to open a malicious file or visit a compromised webpage, to execute code as root.
Business impact
Successful exploitation poses a severe risk to organizational security, as it grants attackers root-level control over the host system. Given the CVSS score of 7.8, this vulnerability represents a high-severity threat that could lead to full system compromise, data exfiltration, or complete service disruption.
Remediation
Immediate Action: Apply the vendor-provided fix found in commit d2cb9cde5c9dc6a6c01735dcb92fe7699ddf6bc5 immediately, as no official versioned patch is currently listed.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected file activity originating from the merge endpoint.
Compensating Controls: Implement strict input validation at the network perimeter and utilize endpoint detection and response tools to flag unauthorized deserialization attempts.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The potential for root-level remote code execution necessitates immediate attention from security teams. Organizations should prioritize the integration of the upstream fix from the official project repository and perform thorough testing to ensure the merge endpoint is properly secured against malicious deserialization payloads.
More Tencent CVEs
Sources
- ZDI-25-1028
- vendor-provided URL Vendor advisory