SourceCodester AI Font Matcher contains a cross-site scripting vulnerability in its webfonts API handling. Font family names are not properly sanitized, allowing malicious JavaScript to be injected through controlled font data returned for webfonts requests and executed in a victim's browser.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-63708, a Cross-Site Scripting (XSS) vulnerability in the 'AI Font Matcher' application distributed by SourceCodester. The repository consists of two files: a detailed README.md describing the vulnerability, impact, and reproduction steps, and a JavaScript file (poc.js) implementing the exploit. The exploit works by hooking the browser's fetch API to intercept requests for 'webfonts', exfiltrating the user's cookies to an attacker-controlled server, and returning a controlled webfonts response. The main attack vector is browser-based XSS, and the exploit demonstrates the risk of arbitrary JavaScript execution and session hijacking. The only fingerprintable endpoint in the code is the exfiltration URL (http://[your-ip]:8001/steal?cookie=), which should be replaced by the attacker's server. The repository is a clear, functional PoC and does not use any exploit frameworks.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.