CVE-2025-27920
HIGH KEVOutput Messenger < 2.0.63 - Path Traversal via File Path Parameter
Title source: llmExploitation Summary
CVE-2025-27920 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 19, 2025.
Description
Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.
References (4)
Core 4
Core References
Vendor Advisory
https://www.outputmessenger.com/cve-2025-27920/
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27920
Mitigation, Third Party Advisory
https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-zero-day-in-output-messenger-for-regional-espionage/
Scores
CVSS v3
7.2
EPSS
0.5053
EPSS Percentile
97.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
active
Automatable
yes
Technical Impact
partial
Details
CISA KEV
2025-05-19
VulnCheck KEV
2025-05-12
ENISA EUVD
EUVD-2025-13464
CWE
CWE-24
Status
published
Products (1)
srimax/output_messenger
< 2.0.63
Published
May 05, 2025
KEV Added
May 19, 2025
Tracked Since
Feb 18, 2026