{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ray-2.56.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ray (2.56.0)"],"_cs_severities":["high"],"_cs_tags":["webapps","directory-traversal","lfi"],"_cs_type":"advisory","_cs_vendors":["Ray Project"],"content_html":"\u003cp\u003eRay version 2.56.0 contains a critical directory traversal and local file inclusion vulnerability within the /api/v0/logs API endpoint. The vulnerability allows an unauthenticated remote attacker to access files outside the intended log directory by supplying a crafted glob filter via the 'glob' parameter. An attacker must possess a valid node_id to interact with the API successfully. This vulnerability has been documented with a functional proof-of-concept exploit which demonstrates the ability to read sensitive files from the underlying host filesystem, such as those within /etc. Ray maintainers have been notified, and a fix is currently under review in GitHub Pull Request 64701.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify Ray dashboard instances accessible over the network, typically on port 6379.\u003c/li\u003e\n\u003cli\u003eAttacker probes the environment to enumerate or discover a valid node_id required for interaction with the /api/v0/logs endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET request to the /api/v0/logs endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the 'node_id' parameter with the discovered identifier.\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious traversal payload into the 'glob' parameter, such as '../../../../etc/*'.\u003c/li\u003e\n\u003cli\u003eThe Ray API processes the glob pattern without sufficient validation, concatenating the malicious path.\u003c/li\u003e\n\u003cli\u003eThe application returns the contents of the requested file or directory within the HTTP response body.\u003c/li\u003e\n\u003cli\u003eAttacker successfully exfiltrates sensitive files from the server's filesystem.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to read arbitrary files on the system running Ray, potentially leading to the exposure of credentials, configuration files, or other sensitive system data. The vulnerability is confirmed to affect Ubuntu 22.04 and RHEL 10.0 deployments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement network access controls to restrict access to the Ray dashboard (default port 6379) to authorized internal networks only.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for HTTP GET requests to '/api/v0/logs' containing directory traversal characters (e.g., '../') in the 'glob' parameter.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule provided in this brief to identify exploitation attempts against the logs API.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided patch once released via the official Ray project repository (GH PR 64701).\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T14:06:04Z","date_published":"2026-08-11T14:06:04Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ray-traversal/","summary":"Ray 2.56.0 contains a directory traversal and local file inclusion vulnerability in the /api/v0/logs endpoint allowing unauthenticated attackers to read arbitrary files.","title":"Directory Traversal and LFI in Ray 2.56.0","url":"https://feed.craftedsignal.io/briefs/2026-08-ray-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Ray (2.56.0)","version":"https://jsonfeed.org/version/1.1"}