LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-27920: Srimax Output Messenger Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 19, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 9, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-27920 to its Known Exploited Vulnerabilities catalog on May 19, 2025, with a federal patch deadline of Jun 9, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or…

CVE-2025-27920 is a directory traversal vulnerability in Srimax Output Messenger. According to CISA, it allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access.

For IT and security teams this matters because readable configuration files, credentials, or other data outside the application’s intended scope can give an attacker a foothold for further movement. Treat the product as a priority for inventory and remediation until the vendor advisory is confirmed and applied.

How it works

The weakness is classified as CWE-22: improper limitation of a pathname to a restricted directory. In this class of flaw, user-supplied path information is not correctly constrained, so an attacker can supply sequences that navigate outside the intended directory tree.

In Srimax Output Messenger the result is the ability to reach files beyond the application’s designed scope. Exact request parameters, endpoints, or traversal sequences are not provided in the public summary; any exploitation details must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

Srimax Output Messenger is typically found in environments that use the product for messaging or output handling. Begin with a full software inventory rather than relying on network scans alone.

How to remediate

Patch first. Apply the vendor update or the specific mitigations named in the official advisory for CVE-2025-27920. CISA’s required action is to apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor fix can be installed, reduce the attack surface with compensating controls that address the directory-traversal class.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches when sensitive files become readable. Ransomware use is not documented for this CVE, yet any successful arbitrary file access still warrants investigation of what was accessible and whether credentials or configuration data were present.

Examine logs for signs of exploitation, rotate any secrets that may have been exposed, and assess whether further lateral movement occurred. Readers can run a free exposure scan of their email address to check whether it appears in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSrimax · Output Messenger
WeaknessCWE-22
Added to CISA KEVMay 19, 2025
Federal patch deadlineJun 9, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities