Ray Project maintains a distributed computing and machine-learning framework used across analytics and AI workloads, with its vulnerability profile centered on the core Ray product and recurring around path-traversal, OS command injection, and authorization-handling flaws. These weakness classes reflect the exposure inherent to a system that orchestrates code execution and file access across worker nodes; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ray Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6019CRITICAL A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. Th | Nov 16, 2023 | 9.8 | 85 | NO | YES |
CVE-2023-6021HIGH LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found h | Nov 16, 2023 | 7.5 | 54 | NO | YES |
CVE-2023-6020HIGH LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication. | Nov 16, 2023 | 7.5 | 48 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ray Project.
Media articles that mention a CVE ID that affects a product developed by Ray Project — matched by CVE ID, not by vendor name.