Earlier quoted context omitted.
The implementation is based on mruby, which is riddled with bugs. I spent some time reversing A Dark Room before it got removed. I am confident that there are bugs allowing ROP, from which point getting CFW is a matter of privesc. We have privesc to bootrom on every firmware version up to 7.x (inclusive). This is obviously bad for nintendo.
Why is this obviously bad for Nintendo?
Things like this are why Nintendo doesn't freely allow save file access, or even allow them to be accessed without encrypting them.
If they work this hard to prevent file loading exploits, you can bet your ass there is contract language to prevent what this guy did.