{"id":"GHSA-xg2h-7cxj-3gvh","summary":"Withdrawn Advisory: Command injection in Ray","details":"# Withdrawn Advisory\nThis advisory is a duplicate of GHSA-6wgj-66m2-xxp2 / CVE-2023-48022.\n\n# Original Description\nAn issue in Anyscale Inc Ray between v.2.9.3 and v.2.40.0 allows a remote attacker to execute arbitrary code via a crafted script.","aliases":["CVE-2024-57000"],"modified":"2026-09-10T03:50:06.203364616Z","published":"2025-02-12T00:32:17Z","withdrawn":"2025-02-14T21:30:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-02-12T19:33:10Z","nvd_published_at":"2025-02-11T23:15:09Z","cwe_ids":["CWE-94"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-57000"},{"type":"WEB","url":"https://github.com/honysyang/Ray.git"},{"type":"PACKAGE","url":"https://github.com/ray-project/ray"}],"affected":[{"package":{"name":"ray","ecosystem":"PyPI","purl":"pkg:pypi/ray"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.9.3"},{"last_affected":"2.40.0"}]}],"versions":["2.10.0","2.11.0","2.12.0","2.20.0","2.21.0","2.22.0","2.23.0","2.24.0","2.30.0","2.31.0","2.32.0","2.32.0rc0","2.33.0","2.34.0","2.35.0","2.36.0","2.36.1","2.37.0","2.38.0","2.39.0","2.40.0","2.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-xg2h-7cxj-3gvh/GHSA-xg2h-7cxj-3gvh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}