CVE-2026-32981 describes a high-severity path traversal vulnerability in Ray Dashboard, impacting Ray versions prior to 2.8.1. This flaw, rated 7.5 CVSS (High), allows an unauthenticated, remote attacker to exploit improper path validation to access and disclose arbitrary local files. Although no public exploit code exists and it is not yet in CISA's KEV catalog, the vulnerability is on an internal "Hot List" and has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.1CPE matchmatch criteria | cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.