Zero-day vulnerability in Output Messenger

Path traversal
CVE-2025-27920

Vulnerability details

Advisory: SB2025051322 - Multiple vulnerabilities in Output Messenger

Vulnerable component: Output Messenger

CVE-ID: CVE-2025-27920

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Description:

The vulnerability allows a remote user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated user can upload malicious files to an arbitrary location on the system and execute them, leading to full system compromise.

Note, the vulnerability is being actively exploited in the wild.