RayGHSA-h3xg-wv58-5p43
Ray OS Command Injection vulnerability
Critical9.8CVE-2023-6019 · Published Nov 16, 2023 · updated Sep 10, 2026
A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| ray PyPI | < 2.8.1 | 2.8.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-78
- Also known as
- CVE-2023-6019, PYSEC-2026-519
More Ray advisories
All Ray| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Nov 272025 | Ray's New Token Authentication is Disabled By Default | Critical | No fix yet |
| Nov 262025 | Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack | Critical | 2.52.0 |
| Mar 62025 | ray vulnerable to Insertion of Sensitive Information into Log File | Medium6.4 | 2.43.0 |
| Nov 282023 | Ray has arbitrary code execution via jobs submission API | Critical9.8 | No fix yet |
| Nov 162023 | Ray Missing Authorization vulnerability | Critical9.3 | 2.8.1 |
| Nov 162023 | Ray Path Traversal vulnerability | Critical9.3 | 2.8.1 |