A command injection exists in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication.
{
"github_reviewed": true,
"nvd_published_at": "2023-11-16T17:15:08Z",
"github_reviewed_at": "2023-11-27T23:21:35Z",
"severity": "CRITICAL",
"cwe_ids": [
"CWE-78"
]
}