CVE-2025-15276 is a remote code execution vulnerability in FontForge's parsing of SFD font source files. Insufficient validation of attacker-controlled SFD data can cause deserialization of untrusted data. A remote attacker can induce a target to open a malicious file or visit a malicious page and execute arbitrary code in the context of the FontForge process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept exploit for CVE-2025-15276, an insecure deserialization issue in FontForge's handling of the SFD PickledData field. It contains two files: a Python exploit generator and a README describing the vulnerability, reproduction steps, and mitigation guidance. The main exploit file, CVE-2025-15276-rce.py, creates a malicious Python pickle object by defining an Exploit class with a __reduce__ method that returns os.system and a hardcoded shell command. The command is a bash reverse shell to 10.10.17.34:5555. The script serializes this object using pickle protocol 0 for ASCII compatibility, escapes the serialized data for inclusion in SFD syntax, and writes a minimal malicious font file named exploit.sfd. The intended effect is that when vulnerable FontForge parses the PickledData field and deserializes it, arbitrary OS command execution occurs. Exploit capability: arbitrary command execution on systems that open the crafted .sfd file with vulnerable FontForge. In the provided configuration, the post-exploitation action is a reverse shell callback. The exploit is not a scanner or detector; it is a payload generator that produces a weaponized input file for client-side or pipeline-side exploitation. Attack path: an attacker delivers exploit.sfd to a user or automated font-processing workflow. Once FontForge opens the file, the deserialization path executes the embedded command with the privileges of the FontForge process. This makes the exploit relevant both for local user interaction and for server-side processing pipelines that ingest untrusted font files. Repository structure is minimal and purpose-built: one Python script as the entry point and one README with context. No framework usage, modularization, or payload customization beyond editing the hardcoded LHOST/LPORT values is present.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.