CVE-2025-13708 is a remote code execution vulnerability affecting Tencent NeuralNLP-NeuralClassifier, specifically within the _load_checkpoint function due to improper validation leading to deserialization of untrusted data. This vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector requiring user interaction (e.g., visiting a malicious page) to achieve high impact on confidentiality, integrity, and availability, with code execution as root. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Tencent | NeuralNLP-NeuralClassifier | CurrentCNA affecteddefault unknown |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.