PatchSiren

ray-project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited ray-project CVE published 2026-08-17

CVE-2025-62593

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T00:00:00.000Z and has not been modified since then. This vulnerability, CVE-2025-62593, is a code injection vulnerability in Ray-Project Ray, which has been added to the CISA Known Exploited Vulnerabilities catalog. The vulnerability affects Ray-Project Ray deployments, potentially allowing attac [truncated]

HIGH ray-project CVE published 2026-05-08

CVE-2026-41486

Ray Data in versions 2.54.0 through 2.54.x registers custom PyArrow extension types globally. When PyArrow parses a Parquet file schema containing these extension types, the `__arrow_ext_deserialize__` method passes metadata bytes directly to `cloudpickle.loads()`, enabling arbitrary code execution during schema parsing before any row data is read. This deserialization of untrusted data (CWE-502) allows c [truncated]

HIGH ray-project CVE published 2026-03-17

CVE-2026-32981

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. The vulnerability allows an attacker to access files outside the intended static directory using traversal sequences, resulting in local file disclosure. This issue has a CVSS score of 8.7 and is considered HIGH severity. The CVE was published on March 17, 2026, and last modified on June 30, [truncated]