Executive brief
Ray is an open-source distributed computing framework used by developers to build scalable applications. A code injection vulnerability in Ray allows attackers to remotely execute arbitrary code on developer machines or Ray-running servers without authentication. This can lead to complete system compromise, data theft, or use of the compromised system for further attacks.
Technical details
Ray-Project Ray contains a code injection vulnerability in its handling of user input, likely in a web-based interface or API endpoint accessible via browsers. The vulnerability does not require authentication and can be triggered through network requests via Firefox and Safari browsers. An attacker can craft malicious requests containing code payloads that are executed on the target system, achieving remote code execution. The vulnerability has been actively exploited in the wild. Patch availability from the Ray-Project maintainers should be checked at their official security advisory channels.
Affected products
- Ray-Project Ray <UNKNOWN>
Timeline
- 2026-08-17: disclosed
- 2026-08-17: exploited: Reported exploited in the wild