CVE-2025-66034
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-29

Last updated on: 2025-12-03

Assigner: GitHub, Inc.

Description
fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttools varLib (or python3 -m fontTools.varLib) script has an arbitrary file write vulnerability that leads to remote code execution when a malicious .designspace file is processed. The vulnerability affects the main() code path of fontTools.varLib, used by the fonttools varLib CLI and any code that invokes fontTools.varLib.main(). This issue has been patched in version 4.60.2.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-29
Last Modified
2025-12-03
Generated
2026-06-16
AI Q&A
2025-11-29
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
fonttools fonttools From 4.33.0 (inc) to 4.60.2 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-91 The product does not properly neutralize special elements that are used in XML, allowing attackers to modify the syntax, content, or commands of the XML before it is processed by an end system.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the fontTools library, specifically in the varLib script used for manipulating fonts. Versions from 4.33.0 up to but not including 4.60.2 have an arbitrary file write vulnerability in the main() code path of fontTools.varLib. When a malicious .designspace file is processed, this vulnerability can lead to remote code execution.

Impact Analysis

If you use the affected versions of fontTools varLib and process untrusted .designspace files, an attacker could exploit this vulnerability to write arbitrary files and execute remote code on your system. This could compromise the security and integrity of your environment.

Mitigation Strategies

Upgrade fontTools to version 4.60.2 or later, as this version contains the patch that fixes the arbitrary file write vulnerability in fontTools.varLib.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-66034. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart