← Vulnerability feed

Vulnerability record · CVE-2025-27920 · published 5 May 2025

CVE-2025-27920: Output Messenger directory traversal allows arbitrary file access

Srimax · Output Messenger

Output Messenger before 2.0.63 mishandles file paths, allowing directory traversal via ../ sequences in parameters. An attacker can read files outside the intended directory, risking configuration leakage and arbitrary file access. The flaw is remotely reachable and requires low privileges.

8.8 CVSS 3.1 High CISA KEV since 19 May 2025 EPSS 1.9% · top 21.7% CWE-24 · CWE-24
8.8CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityCVSS 8.8 and confirmed exploitation in CISA KEV, though EPSS is low and no ransomware use is documented.

What it is

Output Messenger before 2.0.63 mishandles file paths, allowing directory traversal via ../ sequences in parameters. An attacker can read files outside the intended directory, risking configuration leakage and arbitrary file access. The flaw is remotely reachable and requires low privileges.

Impact

An attacker gains read access to sensitive files outside the intended directory, which can expose configuration data and other arbitrary files. This may enable further compromise or information gathering.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity and requires low privileges (PR:L) and no user interaction (UI:N). It is exploited by sending crafted parameters containing ../ sequences to the affected service.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog on 2025-05-19, indicating active exploitation. EPSS probability is 0.01855 (78th percentile), and a Microsoft blog references a zero-day used in espionage.

What to do

  • Upgrade Output Messenger to version 2.0.63 or later.
  • Apply vendor mitigations or discontinue use if patching is not possible, per CISA BOD 22-01 guidance.
  • Restrict network access to the Output Messenger service to trusted users and networks.
  • Monitor for and block traversal sequences (e.g., ../) in application inputs where feasible.

Detection

  • Inspect application and web server logs for requests containing ../ or encoded traversal sequences.
  • Monitor file access events for reads of sensitive files outside expected directories by the Output Messenger process.
  • Use network detection to identify anomalous file path parameters in traffic to the Output Messenger service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-27920 to the Known Exploited Vulnerabilities catalog on 19 May 2025 as "Srimax Output Messenger Directory Traversal Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 9 June 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27920 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2025-27920), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.