← Anyscale

2025 Anyscale Ray — CVE-2025-34351 token auth disabled by default

2025 Unknown records affected Share on X

Data compromised

Database credentials; password hashes; Stripe tokens; Slack tokens

Technical writeup

CVE-2025-34351: token-based authentication disabled by default in Ray 2.52.0. Unauthenticated remote attackers can submit jobs and execute arbitrary code. Real-world exploitation documented: database credentials, password hashes, Stripe tokens, Slack tokens exposed.

Root cause

Authentication disabled by default; design flaw

References