Skip to content
RayGHSA-6wgj-66m2-xxp2

Ray has arbitrary code execution via jobs submission API

Critical9.8CVE-2023-48022 · Published Nov 28, 2023 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
ray
PyPI
<= 2.49.2No fix yet
Details and references

More Ray advisories

All Ray
DateAdvisory
Nov 162023Ray Missing Authorization vulnerability
CVE-2023-6020Critical9.3fixed in 2.8.1
Nov 162023Ray Path Traversal vulnerability
CVE-2023-6021Critical9.3fixed in 2.8.1
Nov 162023Ray OS Command Injection vulnerability
CVE-2023-6019Critical9.8fixed in 2.8.1
Mar 62025ray vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-1979Medium6.4fixed in 2.43.0
Nov 262025Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
CVE-2025-62593Criticalfixed in 2.52.0
Nov 272025Ray's New Token Authentication is Disabled By Default
CVE-2025-34351Criticalno fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.