
I did some independent research into CVE-2025-10952, an unauthenticated arbitrary file read vulnerability in ml-logger's #stream_handler. Chaining the glob endpoint for enumeration with a crafted stream request is enough to read any file on the host, including private #SSH keys, resulting in full root compromise with zero credentials required. The published #CVSS of 5.3 reflects the file-read bug in isolation and significantly understates the impact once it's chained this way. Full technical breakdown, root cause analysis is up on my site. http://khashayarnazarkardeh.com
