-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ray | pip | < 2.8.1 | 2.8.1 |
The vulnerability centers on unauthenticated OS command injection via the cpu_profile parameter. This implies:
While exact code isn't available, the pattern matches CWE-78 scenarios where user input flows into shell commands. The patch notes mention hardening log/file access but also reference dashboard fixes. The critical severity and remote exploitation context strongly suggest a direct command injection in HTTP request handling code.
Ongoing coverage of React2Shell