Anyscale Ray allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment.
{
"github_reviewed": true,
"severity": "CRITICAL",
"cwe_ids": [
"CWE-829",
"CWE-918"
],
"nvd_published_at": "2023-11-28T08:15:06Z",
"github_reviewed_at": "2025-09-30T18:19:55Z"
}