


Perceptive Security
SOC/SIEM Consultancy

An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PH…
Published:
2 February 2026 at 23:00:00
Alert date:
3 February 2026 at 19:04:17
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A critical arbitrary file upload vulnerability has been discovered in the AddFont() function of FPDF library version 1.86 and earlier. The vulnerability allows attackers to execute arbitrary code by uploading a specially crafted PHP file through the affected function. This represents a significant security risk as it provides a direct path for remote code execution. All versions up to and including v1.86 are affected by this vulnerability. Organizations using FPDF library should update to a patched version or implement appropriate security controls.
Technical details
Mitigation steps:
Affected products:
FPDF
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-65875
http://www.fpdf.org
https://advisories.gitlab.com/pkg/composer/tecnickcom/tc-lib-pdf-font/CVE-2024-56520/
https://github.com/Setasign/FPDF
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
