High severity7.5NVD Advisory· Published Mar 17, 2026· Updated Jul 22, 2026
CVE-2026-32981
CVE-2026-32981
Description
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rayPyPI | < 2.8.1 | 2.8.1 |
Affected products
4- Range: <2.8.1
- Range: 0
Patches
Vulnerability mechanics
References
15- packetstorm.news/files/id/215801/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-j3mh-qmjj-xp83ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-32981ghsaADVISORY
- www.vulncheck.com/advisories/ray-dashboard-path-traversal-leading-to-local-file-disclosurenvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/ray/PYSEC-2026-130.yamlghsaWEB
- packetstorm.news/files/id/215801ghsaWEB
- access.redhat.com/errata/RHSA-2026:19712nvd
- access.redhat.com/errata/RHSA-2026:24977nvd
- access.redhat.com/errata/RHSA-2026:42644nvd
- access.redhat.com/errata/RHSA-2026:5809nvd
- access.redhat.com/errata/RHSA-2026:6761nvd
- access.redhat.com/errata/RHSA-2026:6762nvd
- access.redhat.com/security/cve/CVE-2026-32981nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32981.jsonnvd
News mentions
0No linked articles in our index yet.