
Apache FOP + Ghostscript = 💥 Bypassed PostScript escaping using non-breaking spaces (\xa0) to inject commands. Chained with CVE-2025-46646 for Windows RCE. @truffzor Apache won't fix it - just updating the docs 🤷 Full technical details @sigabrt9 https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html
Post summary
The post reveals a proof‑of‑concept that bypasses Apache FOP escaping via non‑breaking spaces to inject Ghostscript commands, chaining with CVE‑2025‑46646 for Windows RCE. It links to technical details but does not provide an exploit script, patch, or evidence of active attacks.

