CVE-2026-32981High· 7.5▾ TwilightA path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
ray < 2.8.1Upgrade past the affected range:
ray 2.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-34351CriticalRay's New Token Authentication is Disabled By Default
CVE-2023-6019Critical· 9.8Ray OS Command Injection vulnerability
CVE-2023-48022Critical· 9.8Ray has arbitrary code execution via jobs submission API
CVE-2023-6020Critical· 9.3Ray Missing Authorization vulnerability
CVE-2023-6021Critical· 9.3Ray Path Traversal vulnerability
CVE-2025-62593CriticalRay is an AI compute engine