PT-2025-19714 · Unknown · Output Messenger
CVE-2025-27920
·
Published
2024-12-25
·
Updated
2026-07-19
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Output Messenger versions prior to 2.0.63
Description
Output Messenger is affected by a directory traversal issue caused by improper file path handling. Remote attackers can use
../ sequences in parameters to access sensitive files outside the intended directory, which may lead to arbitrary file access or the leakage of configuration data. This flaw has been exploited in cyber espionage campaigns by threat actors such as Marbled Dust (also known as Sea Turtle or Cosmic Wolf) targeting Kurdish military personnel in Iraq. In these incidents, the vulnerability was used as an initial access vector to drop malicious payloads and establish control over servers via Golang backdoors for data exfiltration.Recommendations
Update Output Messenger to version 2.0.63 or later.
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Output Messenger