fonttools is vulnerable to Path Traversal
55
Medium Risk
When exporting embedded bitmap data to external files, the EBDT/CBDT code uses the glyph name directly as the output filename. A font with crafted glyph names containing path separators can make the exported bitmap escape the output directory, allowing arbitrary file writes outside the intended folder. Untrusted fonts can also collide filenames so that one glyph overwrites another. The fix percent-encodes unsafe glyph names into an injective, path-separator-free filename.
You are affected if you are using a version that falls within the vulnerable range and you export embedded bitmaps to external files (for example ttx -z extfile) from untrusted fonts.
fonttools is vulnerable to Path Traversal in versions 2.5 - 4.63.0.
Upgrade the fonttools library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.