CVE-2025-66034General(fonttools / fonttools)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for fonttools fonttools systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to remote code execution when a malicious .designspace file is processed. The vulnerability affects the main() code path of fontTools.varLib, used by the fonttools varLib CLI and any code that invokes fontTools.varLib.main(). This issue has been patched in version 4.60.2.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-91

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fonttools

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
fonttools

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-15: 1Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-22: 1Exploit Tool / Code · 2026-03-22: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-22: 103-1503-22
Signal classification2 categories
General
150.0%
PoC
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-151
General1
2026-03-221
PoC1
Full discourse2 posts
  • _brianbundi@bundibrianx
    General

    Just rooted VariaType on @hackthebox_eu! 🚩 LFI source leak via ....// bypass__RCE via FontTools injection (CVE-2025-66034)__Lateral move via filename command injection__Rooted via setuptools PackageIndex path traversal 📈 https://labs.hackthebox.com/achievement/machine/2252974/850 #HackTheBox #HTB #CyberSecurity

    Post summary

    The post recounts exploitation steps for CVE‑2025‑66034 within a HackTheBox lab, noting LFI, RCE and path traversal, but lacks PoC, tool details, active exploitation evidence, or patch info.

    10030215
    6 followersView on X
  • v3cn4@big_notation
    PoC

    Just published my deep dive on CVE-2025-66034 🧵 fontTools varLib → Arbitrary File Write + XML Injection → RCE Two missing sanitization checks. One file upload. Full shell. Full writeup + PoC code 👇 https://v3cn4.medium.com/cve-2025-66034-poc-112bfb1b7044 #CVE #PenTest #OffSec #HTB #RedTeam

    Post summary

    The author delivers a technical deep‑dive into CVE‑2025‑66034, revealing an RCE vector via arbitrary file write and XML injection, and shares PoC code through a provided link.

    00000192
    7 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfonttoolsfonttools-python-

Explore more