VYPR
Critical severity9.8NVD Advisory· Published Nov 28, 2023· Updated Jun 17, 2026

CVE-2023-48022

CVE-2023-48022

Description

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
rayPyPI
<= 2.49.2

Affected products

14

Patches

Vulnerability mechanics

References

14

News mentions

1