{"id":"CVE-2025-27920","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-27920","summary":"Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive…","details":"Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.","published":"2025-05-05T00:00:00.000Z","modified":"2025-10-21T22:55:17.487Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"},"epss":{"score":0.01796,"percentile":0.76802,"asOf":"2026-08-26"},"cisaKev":{"dateAdded":"2025-05-19","dueDate":"2025-06-09","knownRansomwareCampaignUse":false},"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.srimax.com/products-2/output-messenger/"},{"type":"WEB","url":"https://www.outputmessenger.com/cve-2025-27920/"},{"type":"ADVISORY","url":"https://www.microsoft.com/en-us/security/blog/2025/05/12/marbled-dust-leverages-zero-day-in-output-messenger-for-regional-espionage/"},{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-27920"}],"provenance":{"sources":["OSV.dev","NVD","CISA KEV","FIRST.org (EPSS)"],"lastVerified":"2025-10-21T22:55:17.487Z"}}