Junglewise Threat Intelligence

CVE-2023-6021: PYSEC-2026-515 - Ray Path Traversal vulnerability

CVE-2023-6021 · Severity: low · CVSS 3 · Published 2026-06-29

Technologies: Ray. Vendors: PyPI.

Executive brief

Ray is a distributed computing engine used for AI and machine learning workloads. An unauthenticated attacker can read arbitrary files on a Ray server through a path traversal vulnerability in the log API endpoint, potentially exposing sensitive configuration files, credentials, or application data without any authentication required.

Technical details

The vulnerability is a local file inclusion (LFI) in Ray's log API endpoint caused by improper path validation (CWE-22: Improper Limitation of a Pathname to a Restricted Directory, and CWE-29: Path Traversal). The vulnerable endpoint does not properly sanitize user-supplied file path parameters, allowing attackers to traverse directories using sequences like `../` to access files outside the intended log directory. The attack requires only network access to the Ray API endpoint and no authentication; an attacker can directly read arbitrary files on the host system. The vulnerability affects all versions prior to 2.8.1, which contains the fix.

Affected products

  • Ray Ray prior to 2.8.1

Timeline

  • 2023-11-16: disclosed
  • 2023-11-16: patched: Fix released in Ray 2.8.1

References

Related threats