CVE-2025-46646PoC(artifex / ghostscript)

LOWCVSS 4.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

In Artifex Ghostscript before 10.05.0, decode_utf8 in base/gp_utf8.c mishandles overlong UTF-8 encoding. NOTE: this issue exists because of an incomplete fix for CVE-2024-46954.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ghostscript

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-27); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ghostscript

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1PoC Mentioned / Linked · 2026-02-27: 1Technical Details · 2026-02-27: 102-2702-28
Signal classification2 categories
PoC
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-271
PoC1
2026-02-281
General1
Full discourse2 posts
  • Icare@Icare1337
    PoC

    Apache FOP + Ghostscript = 💥 Bypassed PostScript escaping using non-breaking spaces (\xa0) to inject commands. Chained with CVE-2025-46646 for Windows RCE. @truffzor Apache won't fix it - just updating the docs 🤷 Full technical details @sigabrt9 https://offsec.almond.consulting/bypassing-apache-fop-escaping-to-reach-ghostscript.html

    Post summary

    The post reveals a proof‑of‑concept that bypasses Apache FOP escaping via non‑breaking spaces to inject Ghostscript commands, chaining with CVE‑2025‑46646 for Windows RCE. It links to technical details but does not provide an exploit script, patch, or evidence of active attacks.

    13136182.2K
    2.0K followersView on X
  • VulnTracker@vuln_tracker
    General

    @Icare1337 @truffzor @sigabrt9 Thanks for the useful information. You now can see the full details about CVE-2025-46646 from https://vulntracker.io/cves/CVE-2025-46646

    Post summary

    The tweet points to a vulnerability tracker for more information on CVE-2025-46646 but provides no PoC, exploit code, patch, or technical details.

    00010169
    352 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appartifexghostscript---

Explore more