Database/AI/ML frameworks & serving
Ray (dashboard /static/ file handler): Path traversal under the dashboard's /static/ route lets an unauthenticated
Impact
Path traversal under the dashboard's /static/ route lets an unauthenticated caller read any file the Ray process can open. On a GPU head node that typically means cloud instance credentials, kubeconfigs, SSH keys and other tenants' checkpoint paths - enough to pivot into the rest of the cluster. Part of the same 2023 Ray CVE cluster as the ShadowRay job-submission bug.
Who can reach it
Anyone who can issue HTTP requests to the Ray dashboard port (8265). No authentication required.
What to do
Upgrade Ray to 2.8.1 or later and restart the head node. Because the dashboard has no authentication by design in these versions, also restrict port 8265 with a NetworkPolicy or firewall and rotate any credential files that lived on the head node while it was exposed.
References
Related entries
- MLflow (LFI via URI parsing): Local file inclusion — read arbitrary filesCVE-2024-3573 · MLflow (LFI via URI parsing)Critical
- Milvus: Unauthenticated attacker exploits the server directlyCVE-2025-64513 · MilvusCritical
- Obot: quickstart container listens on 0.0.0.0 with auth off, granting anyone admin and the host Docker socketCVE-2026-101065 · Obot AI agent/MCP platform (documented Docker quickstart)Critical
- OpenShift AI guardrails-detectors: unauthenticated blind SSRF and file read via crafted XSDCVE-2026-15378 · Red Hat OpenShift AI guardrails-detectors (XSD schema parsing)Critical
- Jupyter Server: notebook HTML rendered without CSP sandbox gives stored XSS and kernel RCECVE-2026-44727 · Jupyter Server nbconvert HTTP handlers (Content-Security-Policy sandbox directive)Critical
- OpenMed: unauthenticated model_name routes to a trust_remote_code loader and executes attacker codeCVE-2026-47117 · OpenMed privacy-filter model loader (model_name dispatcher, trust_remote_code=True path)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.