PYSEC-2026-518
Ray's New Token Authentication is Disabled By Default
Details
Anyscale Ray 2.52.0 contains an insecure default configuration in which token-based authentication for Ray management interfaces (including the dashboard and Jobs API) is disabled unless explicitly enabled by setting RAY_AUTH_MODE=token. In the default unauthenticated state, a remote attacker with network access to these interfaces can submit jobs and execute arbitrary code on the Ray cluster. NOTE: The vendor plans to enable token authentication by default in a future release. They recommend enabling token authentication to protect your cluster from unauthorized access.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for ray (pip). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-w8vc-465m-jjw6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-34351[ADVISORY]
- https://docs.ray.io/en/latest/ray-security/token-auth.html[WEB]
- https://github.com/ray-project/ray[PACKAGE]
- https://github.com/ray-project/ray/releases/tag/ray-2.52.0[WEB]
- https://www.cve.org/resourcessupport/allresources/cnarules#section_4-1_Vulnerability_Determination[WEB]
- https://www.linkedin.com/posts/jonathan-leitschuh_the-latest-piece-of-mind-bending-research-activity-7396976425997606912-qizE[WEB]
- https://www.oligo.security/blog/shadowray-2-0-attackers-turn-ai-against-itself-in-global-campaign-that-hijacks-ai-into-self-propagating-botnet[WEB]
- https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild[WEB]
- https://www.vulncheck.com/advisories/anyscale-ray-token-authentication-disabled-by-default-insecure-configuration[WEB]
- https://pypi.org/project/ray[PACKAGE]
- https://github.com/advisories/GHSA-gx77-xgc2-4888[ADVISORY]