PT-2025-39399 · Unknown · Geyang Ml-Logger

·

CVE-2025-10951

·

Published

2025-09-25

·

Updated

2026-07-07

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions geyang ml-logger versions prior to acf255bade5be6ad88d90735c8367b28cbe3a743
Description A path traversal issue exists in the log handler function within the ml logger/server.py file. Manipulation of the File argument can lead to unauthorized file access. This issue is potentially exploitable remotely and an exploit is publicly available.
Recommendations Update to a version later than acf255bade5be6ad88d90735c8367b28cbe3a743. As a temporary workaround, restrict access to the ml logger/server.py file. Avoid using the File parameter in the log handler function until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10951
GHSA-8X9J-2P8R-7XC6
PYSEC-2026-1634

Affected Products

Geyang Ml-Logger