
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15276 is a deserialization of untrusted data vulnerability in FontForge's SFD (Spline Font Database) file parser that allows remote attackers to execute arbitrary code. The flaw affects FontForge version 20251009 and was publicly disclosed on December 29, 2025, as a zero-day advisory by the Zero Day Initiative after the vendor rejected the vulnerability report. It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is improper validation of user-supplied data during SFD file parsing, classified as CWE-502 (Deserialization of Untrusted Data). When FontForge processes a maliciously crafted SFD file, it deserializes attacker-controlled data without adequate sanitization, enabling arbitrary code execution in the context of the current process. Exploitation requires user interaction — the target must open a malicious SFD file or visit a malicious page that triggers FontForge file processing. The vulnerability was internally tracked as ZDI-CAN-28198 and credited to researcher volticks (@movx64) (ZDI Advisory).
Successful exploitation grants an attacker arbitrary code execution in the context of the FontForge process, resulting in high impact to confidentiality, integrity, and availability of the affected system. An attacker could read sensitive files accessible to the user running FontForge, modify or destroy data, and potentially use the compromised host as a pivot point for lateral movement within a network. The attack vector is local (the file must be opened by the victim), but the vulnerability is classified as remotely exploitable because an attacker can deliver the malicious SFD file via email, web download, or a malicious webpage (ZDI Advisory, Red Hat Bugzilla).
The vulnerability was published as a zero-day advisory on December 29, 2025, after the vendor rejected the fix request, meaning no patch was available at the time of disclosure. A proof-of-concept exploit reference exists via the ZDI advisory, though no evidence of active in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.22%, indicating a currently low but non-negligible probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog at this time (ZDI Advisory).
.sfd files in user download directories, temporary folders, or email attachment staging areas; new or modified files in user home directories created by the FontForge process shortly after opening an SFD file./bin/bash, cmd.exe, curl, wget, or network utilities); FontForge process making unexpected outbound network connections.No vendor-released patch is currently available; the FontForge maintainers rejected the vulnerability report, stating only pull requests with required fixes would be considered. The primary mitigation recommended by ZDI is to restrict user interaction with FontForge — specifically, avoid opening SFD files from untrusted or unknown sources. Organizations should consider uninstalling FontForge on systems where it is not essential, implement application whitelisting to limit FontForge execution on critical systems, and monitor vendor repositories for community-contributed fixes. Users should also disable any file associations that automatically open SFD files with FontForge (ZDI Advisory, Red Hat Bugzilla).
The vulnerability generated notable attention on social media platforms including Mastodon, Bluesky, and Infosec.Exchange, primarily driven by the unusual circumstance of it being published as a zero-day due to vendor rejection. Security community commentary highlighted the vendor's stance — requiring submitters to provide pull requests with fixes rather than accepting vulnerability reports — as a problematic disclosure policy. Red Hat tracked the issue in their Bugzilla system with high severity, and Tenable published a detection plugin (Nessus plugin 281469). The disclosure was covered by TheHackerWire and aggregated by multiple vulnerability intelligence platforms (ZDI Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."