Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-66034

35
FAUCET Score

CVE-2025-66034 is a critical arbitrary file write vulnerability affecting fontTools versions 4.33.0 through 4.60.1. Specifically, the fontTools varLib script can be exploited when processing a malicious .designspace file, leading to remote code execution. This vulnerability carries a CVSS score of 9.8 (Critical), indicating it can be exploited remotely with low complexity and result in complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 10 mentions, suggesting awareness among security researchers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.33.0, < 4.60.2CPE matchmatch criteria
cpe:2.3:a:fonttools:fonttools:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

6.3MEDIUM

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
1.0
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.51%
Probability of exploitation in next 30 days
EPSS Percentile
40.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0051 is in the 19th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (23)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: fonttoolsFixed in: 4.60.2
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-agent-rhel9:sha256:d88abafc4a46463442434b6622577fdb3ba938496a50c7afe3af3fbb0b2b091e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-controller-rhel9:sha256:8a3021116d34e958681022873a7a249f9331031df1659181a593c9abc48ca697
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-router-rhel9:sha256:584315e5697664ba0a6814033c7bc179bf400aac665627bf1291b83c527ab5d2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-storage-initializer-rhel9:sha256:50731e11aab49e36bb9e5cf23b88ac8591c22df1f98a11c9e65ff0e47f8ae2f9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-llama-stack-core-rhel9:sha256:4f3e402082fd9064ef612b4306ba1da62f7b142d82b0f184b4b6ad65540927a9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:sha256:88fbe21741f4052b4fb118c652e5f39ae28937e8b60fad930945be8ac3351eec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:sha256:0780f52efa6c68ea2fb6371edfbd8b703157c38911803985bb1a676c84e073b5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9:sha256:a202c9ec6be34c4be1793e4f9f348077f345c450e0fcd04071d5092f266df9b4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:sha256:e18d2d006c8cd4e3d3816540e154f421e7550a96f73901a799c15a5b4fe576db
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:sha256:6e8f2fc28114e00d6f46450f111916b5b4efbdc1cee78596d36cd24baaea0c1c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9:sha256:3bdeae6f78230e1d966cf7a3f35ea821c808f40cc4c2abb7af9b1748f5611826
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:sha256:012089e186f66a139d3dbab861f2c88e18c7953b81381872fb5ccf78465ab641
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:sha256:8f3cfa79c68587c251805f01acc84a6a24bc08505a7548a9b3aebc8f58ed8a25
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:sha256:fbe346eafcfbb867f595cbad5ea0190fabbabc61ad80a4be2265e0e2b0149f68
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-pytorch-llmcompressor-cuda-py312-rhel9:sha256:fec8bf2d539fd00df8854a723bae98b7e173c43153c3132ba459bc0e9a86ae35
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:sha256:b19482e4008ac03a39b432fb3056bb1ab372ef1617df5bbfe784bc2910b6827a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:sha256:1213d9e9a56ec3fddb887082d95c2ac168876eee8592aba265aeadd7ffad3898
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-tensorflow-rocm-py312-rhel9:sha256:85abac79e8d09b61a9fffb0b5d3fd2a3f9da65bad9573a72cecb878a81357dcf
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:sha256:b14e6b2a5f4b66dacfcd6c336e2a9e057b1d3ce7de902f0090d9a150a8292a84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-openvino-model-server-rhel9:sha256:84739168d6ea2813c5b9666773166649a6b328a279dac80b61c51311a6a2943a
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-tech-preview/automation-dashboard-rhel9

Vendor Advisories (2)

pipGHSA-768j-98cg-p3fvmedium

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

Dec 1, 2025
redhatCVE-2025-66034Moderate

fonttools: fontTools: Arbitrary file write leading to remote code execution via malicious .designspace file

Nov 29, 2025

References

github.com / fonttools/fonttools/commit/a696d5ba93270d5954f98e7cab5ddca8a02c1e32
Patch
github.com / fonttools/fonttools/security/advisories/GHSA-768j-98cg-p3fv
ExploitVendor Advisory