Database/AI/ML frameworks & serving
Ray (dashboard job submission API, browser-origin guard): Ray's only defense against browser-driven job submission was
Impact
Ray's only defense against browser-driven job submission was a User-Agent check, which Firefox and Safari let an attacker route around via DNS rebinding. A developer merely visiting a malicious web page hands the attacker remote code execution on their Ray cluster - including laptop-local dev clusters that were never meant to be reachable. CISA added this to the KEV catalog on 2026-08-17, so treat it as actively exploited.
Who can reach it
A remote web page loaded in the victim's Firefox or Safari, which then rebinds DNS to reach a Ray dashboard on localhost or on any network the victim's browser can route to. No credentials on the Ray side.
What to do
Upgrade Ray to 2.52.0 or later, then enable token authentication (RAY_AUTH_MODE=token) since the 2.52.0 fix alone does not authenticate the endpoints. Restart head and workers. Given the KEV listing, also audit job history and node processes on any cluster that was reachable from a developer workstation.
References
Related entries
- Flowise: SQLite Record Manager config override gives an authenticated user root code execution in the containerCVE-2026-69259 · Flowise SQLite Record Manager node (additionalConfig database path override)Critical
- Flowise: custom-function sandbox escape via puppeteer.launch gives command execution as the Flowise userCVE-2026-73483 · Flowise (/api/v1/node-custom-function, vm2/@flowiseai/nodevm sandbox)Critical
- TensorFlow / Keras: Arbitrary code execution via unsafe YAML deserialization of model configCVE-2021-37678 · TensorFlow / KerasCritical
- MLflow (tracking server): Path traversal (`\..\filename`)CVE-2023-1177 · MLflow (tracking server)Critical
- Ray (dashboard /static/ file handler): Path traversal under the dashboard's /static/ route lets an unauthenticatedCVE-2023-6020 · Ray (dashboard /static/ file handler)Critical
- MLflow (LFI via URI parsing): Local file inclusion — read arbitrary filesCVE-2024-3573 · MLflow (LFI via URI parsing)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.