-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability involves RCE via crafted scripts in Ray's job submission API (CWE-94). The provided exploit code targets Ray's dashboard service (port 8265) to execute commands through job submissions. This suggests the vulnerability exists in job handling components. While exact code isn't available, Ray's architecture separates dashboard/client interactions (JobSubmissionClient) from backend execution (JobManager). Both components are prime candidates for improper input sanitization when processing job commands. Confidence is medium due to exploit pattern matching and CWE alignment, but limited by the withdrawn advisory and lack of direct code references.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ray | pip | >= 2.9.3, <= 2.40.0 |
KEV Misses 88% of Exploited CVEs- Get the report