CVE-2025-27920: Srimax Output Messenger Directory Traversal Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-05-19. EPSS: 1.9% chance of exploitation in the next 30 days.

Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

Affected products

  • Srimax Output Messenger: before 2.0.63 (fixed in 2.0.63)

Published 2025-05-05. Last modified 2026-06-17.