So, let me see if I get this straight...
cdnjs is a CDN for javascript libraries. cdnjs has a "library update server", in which an "auto-update script" runs periodically to update the libraries that the CDN offers. If it finds a new version of a library, it downloads the files from the library's git repository, and it publishes them on the CDN.
There can be symlinks in git repositories, but the "auto-update script" doesn't handle them correctly. And that's the core of the vulnerability.
If you own the git repository of a library published by cdnjs, you could add a symlink to the git repository. The symlink could point to a file that you want to access on the cdnjs "library update server". Then, as soon as the "auto-update script" runs, the file's contents will be public to everyone on the CDN.
But how would you manage to create a malicious library and have it approved by cdnjs? That's the part of the exploit that sounds the hardest, and I don't see a reasonable way to go about it.