PT-2025-19714 · Unknown · Output Messenger

CVE-2025-27920

·

Published

2024-12-25

·

Updated

2026-07-19

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Output Messenger versions prior to 2.0.63
Description Output Messenger is affected by a directory traversal issue caused by improper file path handling. Remote attackers can use ../ sequences in parameters to access sensitive files outside the intended directory, which may lead to arbitrary file access or the leakage of configuration data. This flaw has been exploited in cyber espionage campaigns by threat actors such as Marbled Dust (also known as Sea Turtle or Cosmic Wolf) targeting Kurdish military personnel in Iraq. In these incidents, the vulnerability was used as an initial access vector to drop malicious payloads and establish control over servers via Golang backdoors for data exfiltration.
Recommendations Update Output Messenger to version 2.0.63 or later.

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06724
CVE-2025-27920

Affected Products

Output Messenger