Deserialization Flaw in Tencent MimicMotion Allows Remote Code Execution
CVE-2025-13716
7.8HIGH
What is CVE-2025-13716?
A vulnerability exists in Tencent MimicMotion's create_pipeline function, which improperly validates user-supplied data. This flaw allows remote attackers to execute arbitrary code on compromised installations when the user interacts with a malicious page or file. By exploiting this vulnerability, an attacker can gain root-level access, risking system integrity and confidentiality.
Affected Version(s)
MimicMotion Current
