© 2025-2026 PySpect
First version without a known vulnerability: 2.56.0
Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
Fixed in: 2.56.0
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Fixed in: 2.55.0
Ray Dashboard is vulnerable to path traversal through its static file handling mechanism
Fixed in: 2.8.1
Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
Fixed in: 2.54.0
Ray's New Token Authentication is Disabled By Default
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Fixed in: 2.52.0
ray vulnerable to Insertion of Sensitive Information into Log File
Fixed in: 2.43.0, 64a2e4010522d60b90c389634f24df77b603d85d
Ray has arbitrary code execution via jobs submission API
Ray Missing Authorization vulnerability
Fixed in: 2.8.1
Ray Path Traversal vulnerability
Fixed in: 2.8.1
Ray OS Command Injection vulnerability
Fixed in: 2.8.1