Exploitation Summary
EIP tracks 2 public exploits for CVE-2024-25081. PoCs published by AliElKhatteb, InzegoSec.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-25081 (FontForge command injection via malicious ZIP filenames) and CVE-2025-47273 (setuptools path traversal for SSH key deployment). Both exploits are complete with reverse shell generation and HTTP server setup.
Description
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
Exploits (2)
The repository contains functional exploit code for CVE-2024-25081 (FontForge command injection via malicious ZIP filenames) and CVE-2025-47273 (setuptools path traversal for SSH key deployment). Both exploits are complete with reverse shell generation and HTTP server setup.
References (6)
Scores
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L