CVE-2023-6019Exploit(ray_project / ray)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A command injection existed in Ray's cpu_profile URL parameter allowing attackers to execute os commands on the system running the ray dashboard remotely without authentication. The issue is fixed in version 2.8.1+. Ray maintainers' response can be found here: https://www.anyscale.com/blog/update-on-ray-cves-cve-2023-6019-cve-2023-6020-cve-2023-6021-cve-2023-48022-cve-2023-48023

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ray

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Exploit: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
ray

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-02: 104-02
Signal classification1 categories
Exploit
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ‘BBWriteups’@bbwriteup
    Exploit

    "CVE-2023–6019 Walkthrough (Proving Ground-OSCP)" by Cyber Public School #BugBounty #Cybersecurity #Hacking #InfoSec https://medium.com/@cyber_public_school/cve-2023-6019-walkthrough-proving-ground-oscp-067cae70085d

    Post summary

    The Medium article titled "CVE‑2023‑6019 Walkthrough (Proving Ground‑OSCP)" presents a step‑by‑step guide to exploiting the vulnerability, but does not provide a functional exploit script, evidence of live attacks, or patch information.

    00000100
    563 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appray_projectray---

Explore more