Executive brief
A security vulnerability has been identified in the Ray Dashboard, a tool used to monitor and manage distributed AI and machine learning workloads. An attacker can exploit this flaw to bypass security restrictions and read sensitive files directly from the server's local storage. This could lead to the exposure of configuration files, credentials, or other private data, potentially compromising the entire AI infrastructure.
Technical details
A path traversal vulnerability exists in the Ray Dashboard's static file handling mechanism due to improper validation and sanitization of user-supplied input. By sending specially crafted requests containing traversal sequences (e.g., '../'), an unauthenticated remote attacker can access arbitrary files on the host system that are readable by the Ray process. The vulnerability is located in the component serving static assets, typically listening on port 8265. This issue was addressed in Ray version 2.8.1 by implementing stricter path validation. Red Hat has also issued advisories for affected products that bundle Ray, such as OpenShift AI.
Affected products
- Anyscale Ray < 2.8.1
- Red Hat Red Hat OpenShift AI 2.25, 3.3
- Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3
- Red Hat Red Hat AI Inference Server 3.2
Timeline
- 2026-03-17: disclosed
- 2026-03-17: advisory
- 2026-05-20: patched: Red Hat released patches for OpenShift AI via RHSA-2026:19712
References
- https://github.com/ray-project/ray
- https://packetstorm.news/files/id/215801/
- https://www.vulncheck.com/advisories/ray-dashboard-path-traversal-leading-to-local-file-disclosure
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:5809
- https://access.redhat.com/errata/RHSA-2026:6761