2025 Anyscale Ray — CVE-2025-34351 token auth disabled by default
Data compromised
Database credentials; password hashes; Stripe tokens; Slack tokens
Technical writeup
CVE-2025-34351: token-based authentication disabled by default in Ray 2.52.0. Unauthenticated remote attackers can submit jobs and execute arbitrary code. Real-world exploitation documented: database credentials, password hashes, Stripe tokens, Slack tokens exposed.
Root cause
Authentication disabled by default; design flaw