CVE-2025-66034 is an arbitrary file write vulnerability in fontTools varLib affecting versions 4.33.0 through 4.60.1. Processing a malicious .designspace file through the fontTools.varLib main() code path, including the varLib command-line interface, permits attacker-controlled file writing. The arbitrary write can be leveraged for remote code execution in contexts where written files can affect code or configuration execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
8 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is primarily a collection of HackTheBox writeups, but it also contains real exploit automation in the `VariaType/` directory. The actionable exploit consists of one Bash orchestrator (`exploit_variatype.sh`) and four Python phase scripts. The exploit is not tied to a common framework like Metasploit; it is custom automation for a multi-stage Linux target compromise. Main exploit capabilities: (1) reconnaissance and extraction of credentials from an exposed `.git` repository on `portal.variatype.htb`; (2) login and LFI verification against `download.php`; (3) preparation of malicious font files and a crafted designspace document to exploit CVE-2025-66034 in fontTools varLib, causing arbitrary file write of a PHP webshell to `/var/www/portal.variatype.htb/public/files/shell.php`; (4) privilege escalation to user `steve` using a ZIP filename command injection payload associated with CVE-2024-25082, which appends an attacker SSH key into `/home/steve/.ssh/authorized_keys`; and (5) privilege escalation to root by abusing `sudo /usr/bin/python3 /opt/font-tools/install_validator.py` with a URL-encoded absolute path traversal to write the attacker’s public key into `/root/.ssh/authorized_keys`. Repository structure: most files are Markdown writeups for HTB machines/challenges. Only 5 files contain exploit code, all under `VariaType/`. `phase1_git_extract.py` handles exposed Git extraction and credential recovery. `phase2_rce_exploit.py` generates malicious font/designspace artifacts for the webshell stage, though upload is partly left manual in that script. `phase3_privesc_steve.py` generates an SSH key, builds an evil ZIP with a filename-based command injection payload, serves it over HTTP, and attempts to place it on the target for later processing. `phase4_privesc_root.py` serves a root public key and invokes the vulnerable validator script over SSH as steve to gain root SSH access. `exploit_variatype.sh` ties the phases together into a mostly automated end-to-end attack. Overall, this is a valid exploit repository with operational code, not just detection logic. The exploit targets a web-exposed Linux application stack and culminates in full root compromise with SSH persistence.
Repository contains a single Python exploit script and a README. The exploit targets the Hack The Box VariaType variable font generator and claims CVE-2025-66034. Structure is minimal: README.md documents usage and exploit theory; exploit.py is the operational entry point. The script automates three stages: (1) generate two minimal valid TTF master fonts using fontTools (source-light.ttf and source-regular.ttf), (2) build a malicious .designspace XML file whose <labelname> metadata embeds a PHP reverse shell payload inside CDATA, and (3) submit the designspace plus both TTFs to the target processing endpoint as multipart/form-data. The XML also sets the output filename for the generated variable font to an attacker-controlled path ending in a randomized shell_<6 chars>.php under /var/www/portal.variatype.htb/public, indicating an arbitrary file write/path traversal style abuse. Main exploit capability: remote code execution by causing the server-side font generation workflow to write attacker-controlled PHP content into the webroot, then invoking that PHP file over HTTP. The payload is a hardcoded PHP reverse shell using fsockopen and proc_open('/bin/bash -i', ...) to connect back to an operator-supplied IP and port. The exploit does not itself trigger the shell URL after upload; it logs the randomized filename and expects the operator to browse/curl to it manually. Notable implementation details: argparse parameters allow customization of attacker IP, port, target filesystem path, and target URL; requests is used for the POST; a browser-like User-Agent is set; shell filenames are randomized with secrets/string. No vulnerability verification logic or cleanup is included. This is a real exploit script rather than a detector, and its payload is basic but functional, making it best classified as OPERATIONAL rather than a mere PoC.
Repository contains a small standalone exploit with two files: a README describing the vulnerability chain and usage, and a single Python exploit script. The exploit targets CVE-2025-66034 in fontTools varLib by chaining two primitives: XML injection through crafted content embedded in a .designspace file and arbitrary file write through an absolute-path filename that bypasses the intended output directory when joined with os.path.join(). The script is not part of a larger exploitation framework. The Python script is the main entry point. It parses attacker-controlled parameters for callback IP/port, vulnerable upload URL, server-side writable webroot path, and public shell URL. It generates minimal master TTF fonts using fontTools.FontBuilder, crafts a malicious .designspace XML document containing injected PHP content and an absolute output filename, uploads the designspace plus master fonts to the target processing endpoint, then requests the resulting PHP file over HTTP to trigger execution. After triggering, it can start a listener using nc or pwncat-cs and attempts shell interactivity improvements such as PTY spawning. Primary exploit capability is unauthenticated remote code execution in a web application context, assuming the vulnerable service exposes font processing and writes generated output into a PHP-executable web-served directory. Fingerprintable targets in the code include the default processing endpoint path /tools/variable-font-generator/process, default filesystem write target /var/www/html/files, and default shell trigger base URL http://variatype.htb/files, along with additional example HTB-style endpoints in the README and CLI examples. Overall, this is an operational PoC exploit that automates end-to-end exploitation from payload generation through upload, trigger, and shell handling.
This repository is a small standalone exploit PoC for CVE-2025-66034 and contains two files: a README describing the vulnerability and attack chain, and a single Python entry point, exploit.py, implementing the exploit workflow. The code is not part of a larger framework. The exploit targets applications that accept user-supplied .designspace files and process them with fontTools varLib. It abuses two behaviors described in the repository: attacker control over the output filename/path in the <variable-font filename="..."> attribute, and unsanitized propagation of XML label content into the generated font output. The script builds a malicious designspace document that embeds a PHP webshell in a <labelname> CDATA section and sets the output filename to an arbitrary server path chosen by the operator. It also includes an embedded base64-encoded minimal valid TTF master so the upload is self-contained. Repository structure and purpose: - README.md: explains the vulnerability, attack chain, requirements, and example usage. - exploit.py: full exploit implementation with argument parsing, payload generation, upload logic, command execution, interactive shell support, and reverse shell triggering. Main capabilities in exploit.py: - build_designspace(output_path): creates the malicious XML designspace payload with a PHP webshell and attacker-controlled output path. - plant_shell(process_url, write_path): sends a multipart/form-data POST containing config.designspace and source-regular.ttf to the vulnerable processing endpoint. - exec_cmd(shell_url, cmd, session): invokes the planted webshell by sending a command through the cmd parameter and parses command output from the returned binary/font response using known markers and BeautifulSoup cleanup. - interactive_shell(...): provides a pseudo-interactive command loop over the webshell. - trigger_revshell(...): sends a reverse shell command through the webshell, using base64 wrapping to reduce escaping issues. - parse_args()/main(): CLI handling for exec, interactive, and revshell modes. The exploit is operational rather than a simple detector: it performs the full chain from upload to code execution. It requires operator-supplied target URLs and write path, with no hardcoded victim infrastructure. Fingerprintable targets are therefore mostly example endpoints and file paths shown in the README and the multipart filenames/cookie/parameter names used by the code. Overall, the repository’s purpose is to demonstrate arbitrary file write leading to RCE against a vulnerable fontTools-backed web service, typically by planting a PHP webshell into a web-accessible path.
This repository is a small standalone exploit containing one Python script and one README. The main file, CVE-2025-66034.py, targets CVE-2025-66034, described here as a path traversal issue in fontTools designspace processing as used by the VariaType HTB target. The exploit is not part of a larger framework. The script builds two minimal TTF font files with attacker-controlled PHP embedded in the font name table (`familyName`). It then generates a malicious `.designspace` XML where the `variable-font filename` attribute contains directory traversal sequences pointing to PHP files under the target web root. These artifacts are uploaded to the target endpoint `/tools/variable-font-generator/process`. If the backend processes the designspace with a vulnerable fontTools workflow, it writes the generated output to the traversed path, effectively planting a PHP file in a web-accessible location. The exploit supports two payload modes: a simple webshell (`system($_GET["c"])`) and a more capable PHP reverse shell that uses `fsockopen`, `proc_open`, and `/bin/bash -i` to connect back to an attacker listener. In webshell mode, the script probes `http(s)://portal.<host>/shell.php` and `/public/shell.php` by sending `?c=id`, checks for `uid=` in the response, and then offers an interactive command loop that sends arbitrary commands via the `c` GET parameter. In reverse-shell mode, it deploys the PHP payload and triggers it with a GET request, instructing the operator to wait on a netcat listener. Repository structure is minimal: the Python exploit contains all logic for payload generation, malicious designspace creation, upload, shell verification, and interaction; the README documents installation, usage examples, and the expected host mappings. Overall, this is an operational exploit for remote file write leading to command execution/RCE against a specific vulnerable web application workflow.
This is a small standalone Python exploit repository with three files: a brief README, a requirements file, and a single executable script, exploit.py. The script is the sole functional component and serves as the entry point. It uses requests for HTTP interaction, base64 to decode an embedded TTF payload, and BeautifulSoup to strip HTML/XML markup from the returned webshell output. The exploit performs a two-stage attack against the Variatype Hack The Box target. First, it sends a multipart/form-data POST request to http://variatype.htb/tools/variable-font-generator/process containing a crafted designspace XML file and a minimal font file. The XML embeds PHP code inside a label field and abuses the variable-font filename attribute with a deep relative path traversal to force the application to write a file to ../../../../../../../../../var/www/portal.variatype.htb/public/files/webshell.php. The written content becomes a PHP webshell containing system($_REQUEST["cmd"]). Second, after attempting the file write, the script issues a GET request to http://portal.variatype.htb/files/webshell.php?cmd={command}, where the command is taken directly from the first command-line argument. It then parses the response and extracts command output between static markers present in the generated file content. This gives the operator remote command execution and is suitable for initial access or launching a reverse shell, as shown in the README examples. Repository purpose: provide a practical RCE exploit for the HTB Variatype challenge by chaining unsafe font/designspace processing with arbitrary file write into a web-accessible PHP location. The code is operational rather than a mere proof of concept because it automates both webshell deployment and command execution, but it is not framework-based and has hardcoded target hosts and paths.
This repository is a small, focused exploit PoC consisting of a README and a single Python script, exploit.py. The script targets a VariaType font-generation workflow and abuses a path traversal/arbitrary file write condition in the variable font generator endpoint. It programmatically builds two minimal TTF files using fontTools, embedding PHP code in the font name table (familyName set to '<?php system($_GET["c"]); ?>'). It then generates a malicious designspace XML document whose variable-font filename field is replaced with a traversal path pointing into the target web root, causing the server to write output as shell.php. Exploit flow: (1) build crafted TTF masters, (2) upload them with a malicious designspace file to http://variatype.htb/tools/variable-font-generator/process, (3) try several traversal depths/paths to place the shell under /var/www/portal.variatype.htb/public/ or a nearby location, (4) probe the resulting shell URL with c=id, and (5) if successful, drop into an interactive HTTP-based command shell. The clean() helper extracts printable command output from the returned binary/font data, indicating the vulnerable application may embed output in generated TTF content. The exploit is clearly functional rather than merely demonstrative: it contains a real payload, automatic upload logic, shell verification, fallback traversal paths, and an interactive operator loop. It is not part of a larger exploit framework. The README confirms intended usage and shows a demo including post-exploitation with a reverse shell command. Overall, the repository’s purpose is to achieve remote code execution on the HTB VariaType target by converting a file-write primitive in the font generator into a PHP web shell deployment.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-66034 in the fontTools varLib variable font generation pipeline. It contains only two files: a README describing the vulnerability and usage, and a single executable script, varlib_cve_2025_66034.py, which implements the exploit end-to-end. The script’s purpose is to exploit an arbitrary file write condition by crafting a malicious .designspace document whose variable-font output filename is set to an attacker-chosen path. It first generates two minimal compatible TTF master fonts locally using fontTools (source-light.ttf and source-regular.ttf). It then builds a PHP reverse shell payload that uses fsockopen to connect back to the attacker and proc_open to run /bin/bash -i. That PHP is embedded into the generated XML designspace content, while the output filename attribute is set to a chosen target path plus a randomized shell filename such as shell_<random>.php. Operational flow: parse CLI arguments (--ip, --port, optional --path, --url, --no-listen), generate the two source fonts, generate a random PHP filename, create the malicious designspace XML, upload all three files to the target via multipart/form-data POST, optionally start a local netcat listener, and finally send an HTTP GET request to a web-accessible path to trigger the uploaded PHP shell. The upload endpoint is configurable, defaulting to http://localhost/tools/variable-font-generator/process. The filesystem write path is configurable, defaulting to /var/www/mysite/public/files. However, the trigger URL is hardcoded to http://portal.variatype.htb/files/{shell_name}, indicating the PoC was tailored to a specific lab/HTB-style target and may require code modification for other environments. The exploit is not a scanner or detection script; it is an actual exploitation tool with a working payload. It is best classified as OPERATIONAL rather than WEAPONIZED because it includes a hardcoded/basic PHP reverse shell and some target-specific assumptions, but it does automate the full attack chain from payload generation through triggering. One code quality issue is that sys.exit is called without importing sys, which would cause an exception only if the invalid-port branch is reached. Otherwise, the exploit logic is coherent and clearly intended to achieve remote code execution via arbitrary file write into a web-served PHP location.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.