{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ml-logger/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2025-10951"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ml-logger"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","web-application"],"_cs_type":"advisory","_cs_vendors":["Geyang"],"content_html":"\u003cp\u003eCVE-2025-10951 is an unauthenticated path traversal vulnerability affecting the \u003ccode\u003egeyang/ml-logger\u003c/code\u003e library in versions up to 0.10.36. The vulnerability exists within the \u003ccode\u003eml_logger/server.py\u003c/code\u003e component, specifically within the \u003ccode\u003elog_handler\u003c/code\u003e and \u003ccode\u003estream_handler\u003c/code\u003e functions. This flaw allows remote, unauthenticated attackers to traverse the file system and access unauthorized files on the hosting server. Publicly available proof-of-concept (PoC) code has been released, significantly lowering the barrier for exploitation. Defenders should prioritize updating instances of \u003ccode\u003eml-logger\u003c/code\u003e to a secure version to mitigate the risk of unauthorized file disclosure or system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation allows an attacker to bypass file system restrictions to read arbitrary files, which may lead to the exposure of sensitive credentials, configuration files, or other proprietary information. Organizations utilizing \u003ccode\u003eml-logger\u003c/code\u003e in web-facing server environments are at the highest risk, as the vulnerability requires no authentication or user interaction to exploit.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003egeyang/ml-logger\u003c/code\u003e to a version beyond 0.10.36 immediately to patch the vulnerable \u003ccode\u003elog_handler\u003c/code\u003e and \u003ccode\u003estream_handler\u003c/code\u003e code.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests containing directory traversal sequences (e.g., \u003ccode\u003e../\u003c/code\u003e, \u003ccode\u003e..%2f\u003c/code\u003e) directed toward the \u003ccode\u003eml-logger\u003c/code\u003e server endpoint.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the \u003ccode\u003eml-logger\u003c/code\u003e server interface to trusted IP addresses if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T05:02:51Z","date_published":"2026-08-26T05:02:51Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2025-10951/","summary":"An unauthenticated path traversal vulnerability (CVE-2025-10951) in the geyang/ml-logger library enables attackers to perform arbitrary file access via the log_handler and stream_handler components.","title":"Unauthenticated Path Traversal in geyang/ml-logger","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2025-10951/"}],"language":"en","title":"CraftedSignal Threat Feed - Ml-Logger","version":"https://jsonfeed.org/version/1.1"}