CVE-2025-66034
fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to remote code execution when a malicious .designspace file is processed. The vulnerability affects the main() code path of fontTools.varLib, used by the fonttools varLib CLI and any code that invokes fontTools.varLib.main(). This issue has been patched in version 4.60.2.
- Fonttools
- < 4.60.2
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.5% (44th percentile)
- Weakness
- CWE-91
- NVD status
- Analyzed
- Published
- 2025-11-29
CVE-2025-66034 at NVD
14 known exploits for CVE-2025-66034
Proof-of-concept code and exploit modules indexed by Sploitus
POC-CVE-2025-66034
CVE-2025-66034
CVE-2025-66034-htb-ctf
Variatype.htb-CVE-2025-66034
varlib-cve-2025-66034
CVE-2025-66034
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools
Exploit for XML Injection (aka Blind XPath Injection) in Fonttools