CVE-2026-32981
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
17/03/2026
Last modified:
19/03/2026
Description
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:* | 2.8.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



