Path traversal in fontTools - CVE-2025-66034
Published: November 28, 2025 / Updated: April 1, 2026
Vulnerability identifier: #VU118845
CSH Severity: High
CVSS v4: 8.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66034
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing .designspace files in fontTools.varLib. A remote attacker can trick the victim into passing a specially crafted file and overwrite arbitrary files on the system.
Affected software
fontTools
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Anolis OS
IBM Concert Software
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - Visual Inspection Component
fonttools (Ubuntu package)
python311-FontTools
python3-fonttools+symfont
fonttools-doc
python3-fonttools
python3-fonttools+woff
python3-fonttools+unicode
python3-fonttools+ufo
python3-fonttools+type1
python3-fonttools+plot
python3-fonttools+lxml
python3-fonttools+interpolatable
python3-fonttools+graphite
fonttools
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Package Hub 15
openSUSE Leap
Ubuntu
Anolis OS
IBM Concert Software
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Maximo Application Suite - Visual Inspection Component
fonttools (Ubuntu package)
python311-FontTools
python3-fonttools+symfont
fonttools-doc
python3-fonttools
python3-fonttools+woff
python3-fonttools+unicode
python3-fonttools+ufo
python3-fonttools+type1
python3-fonttools+plot
python3-fonttools+lxml
python3-fonttools+interpolatable
python3-fonttools+graphite
fonttools
How to mitigate CVE-2025-66034
Install updates from vendor's website.
fontTools - update to 4.60.2
IBM Concert Software - update to 2.2.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1
Maximo Application Suite - Visual Inspection Component - update to 9.1.10
fonttools (Ubuntu package) - addressed in versions 4.29.1-2ubuntu0.1~esm1, 4.46.0-1ubuntu0.1~esm1, 4.55.3-2ubuntu0.25.04.1, 4.55.3-2ubuntu0.25.10.1
python311-FontTools - update to 4.47.2-150600.3.3.1
python3-fonttools+symfont - update to 4.61.0-1
fonttools-doc - update to 4.61.0-1
python3-fonttools - update to 4.61.0-1
python3-fonttools+woff - update to 4.61.0-1
python3-fonttools+unicode - update to 4.61.0-1
python3-fonttools+ufo - update to 4.61.0-1
python3-fonttools+type1 - update to 4.61.0-1
python3-fonttools+plot - update to 4.61.0-1
python3-fonttools+lxml - update to 4.61.0-1
python3-fonttools+interpolatable - update to 4.61.0-1
python3-fonttools+graphite - update to 4.61.0-1
fonttools - update to 4.61.0-1
IBM Concert Software - update to 2.2.0
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.3.1
Maximo Application Suite - Visual Inspection Component - update to 9.1.10
fonttools (Ubuntu package) - addressed in versions 4.29.1-2ubuntu0.1~esm1, 4.46.0-1ubuntu0.1~esm1, 4.55.3-2ubuntu0.25.04.1, 4.55.3-2ubuntu0.25.10.1
python311-FontTools - update to 4.47.2-150600.3.3.1
python3-fonttools+symfont - update to 4.61.0-1
fonttools-doc - update to 4.61.0-1
python3-fonttools - update to 4.61.0-1
python3-fonttools+woff - update to 4.61.0-1
python3-fonttools+unicode - update to 4.61.0-1
python3-fonttools+ufo - update to 4.61.0-1
python3-fonttools+type1 - update to 4.61.0-1
python3-fonttools+plot - update to 4.61.0-1
python3-fonttools+lxml - update to 4.61.0-1
python3-fonttools+interpolatable - update to 4.61.0-1
python3-fonttools+graphite - update to 4.61.0-1
fonttools - update to 4.61.0-1
Links to Public Exploits and PoC-codes
- Exploit #12542 - fonttools-varlib-cve-2025-66034-rce.py (Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, enabling arbitrary file writes. The script automates pay (April 1, 2026)
- Exploit #12535 - varlib-cve-2025-66034 (Proof-of-concept exploit for CVE-2025-66034 in the fontTools variable font generation pipeline. A crafted .designspace file allows control of the output path, enabling arbitrary file writes. The script automates payload creation, fo (April 1, 2026)
- Exploit #12530 - CVE-2025-66034 (CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in fontTools.varLib.) (April 1, 2026)
- Exploit #12528 - CVE-2025-66034 (CVE-2025-66034 exploit and documentation) (April 1, 2026)
External References
Related Security Bulletins
- Arbitrary file write in fontTools
- Ubuntu update for fonttools
- SUSE update for python-FontTools
- Anolis OS update for fonttools
- Multiple vulnerabilities in IBM Concert Software
- IBM Watson Speech Services Cartridge update for fontTools
- IBM Maximo Application Suite - Visual Inspection Component update for fontTools