
CISA added CVE-2024-5274 to the KEV catalog after confirming active exploitation. The flaw is a critical deserialization bug in Ray, the Python-native distributed compute framework used to scale ML/AI workloads. Untrusted data hits the jobs API, arbitrary code runs in the cluster. Ray is infrastructure for training and serving models at scale. If you're running it internet-exposed without auth, you're one HTTP request away from full cluster compromise. Patch or isolate before public exploits catch up to what attackers already have. https://nvd.nist.gov/vuln/detail/CVE-2024-5274 #cybersecurity #infosec
Post summary
CISA reports active exploitation of CVE-2024-5274, a critical deserialization flaw in Ray that enables arbitrary code execution; immediate patching or isolation is recommended.
