CVE-2023-6021: Ray Project Ray

High severity, CVSS 7.5. EPSS: 37.1% chance of exploitation in the next 30 days.

LFI in Ray's log API endpoint allows attackers to read any file on the server without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

Affected products

Published 2023-11-16. Last modified 2026-06-17.