Loading HuntDB...

GHSA-h3xg-wv58-5p43

GitHub Security Advisory

Ray OS Command Injection vulnerability

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.

Affected Packages

PyPI ray
Affected versions: 0 (fixed in 2.8.1)

Related CVEs

Key Information

GHSA ID
GHSA-h3xg-wv58-5p43
Published
November 16, 2023 6:30 PM
Last Modified
January 9, 2025 11:37 PM
CVSS Score
9.0 /10
Primary Ecosystem
PyPI
Primary Package
ray
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.