216.73.217.22

CVE-2026-32981

· Published 17/03/2026 20:16 · Modified 18/03/2026 14:52

Labels: CVE-2026-32981 2026-03-17CVE-2026-32981CWE-22[email protected]

Essential information

Published
17/03/2026 20:16
Modified
18/03/2026 14:52
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ray / rays dashboard cpe:2.3:a:ray:rays_dashboard:<2.8.1:*:*:*:*:*:*:*

References