A security flaw has been discovered in geyang ml-logger up to acf255bade5be6ad88d90735c8367b28cbe3a743. Affected by this issue is the function stream_handler of the file ml_logger/server.py of the component File Handler. Performing manipulation of the argument key results in information disclosure. The attack can be initiated remotely. The exploit has been released to the public and may be exploited. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This is a small standalone Python proof-of-concept repository consisting of one executable exploit script, a technical README, and a requests dependency declaration. CVE-2025-10952.py accepts --target, optional --port (default 8081), --glob, --read, and --out arguments. It constructs an HTTP base URL from the supplied target, sends POST JSON requests to /glob to enumerate matching paths, and sends GET requests with a JSON key field to /stream to retrieve file content. The core exploit condition is the alleged lack of path-containment validation in ml-logger's stream_handler: supplying a key beginning with // is intended to escape the handler's restricted base path. The script has basic request error handling and can save retrieved binary content locally, but includes no shell, command execution, persistence, scanning loop, or post-exploitation automation. README documentation describes follow-on use of a stolen SSH key, but that SSH usage is not implemented by the Python exploit itself.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.