<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sanidhya Soni</title><link>https://sanidhya.tech/</link><description>I build and harden security systems, informed by knowing exactly how they break.</description><language>en-us</language><lastBuildDate>Thu, 03 Sep 2026 11:56:43 +0000</lastBuildDate><atom:link href="https://sanidhya.tech/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-65875: Untrusted Font Upload / Path Injection Can Lead to PHP Execution When Using FPDF</title><link>https://sanidhya.tech/posts/security-research/cve-2025-65875-fpdf-rce-vulnerability/</link><pubDate>Sun, 01 Feb 2026 00:00:00 +0000</pubDate><guid>https://sanidhya.tech/posts/security-research/cve-2025-65875-fpdf-rce-vulnerability/</guid><description>FPDF’s font definitions are PHP and are included at runtime; if an app allows attacker-controlled font definition paths/files, it can lead to code execution.</description></item></channel></rss>