PT-2026-25933 · Anyscale · Ray
Indoushka
·
Publicado
2026-03-17
·
Atualizado
2026-03-18
·
CVE-2026-32981
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ray versions prior to 2.8.1
Description
A path traversal issue exists in Ray Dashboard (default port 8265). Insufficient validation and sanitization of user-supplied paths within the static file handling mechanism allows an attacker to use traversal sequences (e.g., ../) to access files outside the intended static directory, leading to local file disclosure. The vulnerable component is the static file handling mechanism. The API endpoint is not explicitly mentioned. The vulnerable parameter is the user-supplied path.
Recommendations
Update to Ray version 2.8.1 or later.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ray