Vulnerability record · CVE-2023-48022 · published 28 November 2023
CVE-2023-48022: Anyscale Ray job submission API allows unauthenticated remote code execution
Anyscale · Ray
Anyscale Ray versions 2.6.3 and 2.8.0 expose a job submission API that lets a remote attacker execute arbitrary code. The vendor disputes the report, stating Ray is not meant to run outside a strictly controlled network and that token authentication is available from version 2.52.0 onward. Because the API is reachable over the network with no credentials, any exposed Ray dashboard or job endpoint is a direct code execution path.
Description
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS of 9.8 and very high EPSS, with public exploit tooling already circulating.
What it is
Anyscale Ray versions 2.6.3 and 2.8.0 expose a job submission API that lets a remote attacker execute arbitrary code. The vendor disputes the report, stating Ray is not meant to run outside a strictly controlled network and that token authentication is available from version 2.52.0 onward. Because the API is reachable over the network with no credentials, any exposed Ray dashboard or job endpoint is a direct code execution path.
Impact
An attacker gains arbitrary code execution on the Ray node, which typically means full control of the host, its data and any credentials or cluster resources it can reach. In a shared or internet-facing deployment this can pivot into the wider environment.
Attack surface
Reached over the network via the Ray job submission API (CVSS AV:N, PR:N, UI:N), so no authentication and no user interaction are required. The flaw is only exploitable where Ray is exposed beyond a strictly controlled network, which the vendor says is unsupported.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.83942, 99.7th percentile) and public exploit write-ups exist, including a Bishop Fox advisory tagged Exploit and a Vicarius post on the ShadowRay campaign. This indicates active, practical exploitation rather than a theoretical issue.
What to do
- Upgrade Ray to a version with token authentication (2.52.0 or later) and enable it, or apply the vendor's current security guidance.
- Never expose the Ray dashboard or job submission API to untrusted networks; bind to localhost or a private interface and restrict with firewall rules or a VPN.
- Require authentication and authorization in front of any Ray endpoint using a reverse proxy or service mesh if Ray itself cannot enforce it.
- Isolate Ray clusters in a dedicated, segmented network with least-privilege credentials and no access to sensitive internal services.
- Monitor for unexpected job submissions and audit cluster nodes for unauthorized processes or outbound connections.
Detection
- Alert on POST requests to Ray job submission endpoints from unexpected source IPs or outside the cluster network.
- Monitor Ray dashboard and job API logs for job submissions that were not initiated by known users or automation.
- Hunt for new processes, reverse shells or unusual outbound connections originating from Ray worker nodes.
- Track Ray versions in inventory and flag any deployment below 2.52.0 that is network-reachable.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-48022 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-48022), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.