PT-2025-39399 · Unknown · Geyang Ml-Logger
0X1F
·
Published
2025-09-25
·
Updated
2025-09-25
·
CVE-2025-10951
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
geyang ml-logger versions prior to acf255bade5be6ad88d90735c8367b28cbe3a743
Description
A path traversal issue exists in the
log handler function within the ml logger/server.py file. Manipulation of the File argument can lead to unauthorized file access. This issue is potentially exploitable remotely and an exploit is publicly available.Recommendations
Update to a version later than acf255bade5be6ad88d90735c8367b28cbe3a743.
As a temporary workaround, restrict access to the
ml logger/server.py file.
Avoid using the File parameter in the log handler function until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geyang Ml-Logger