Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment
https://thehackernews.com/2024/08/researchers-identify-over-20-supply.html
https://cloud.google.com/support/bulletins#gcp-2024-020
https://www.oligo.security/blog/shadowray-attack-ai-workloads-actively-exploited-in-the-wild
https://www.vicarius.io/vsociety/posts/shadowray-cve-2023-48022-exploit
https://docs.ray.io/en/latest/ray-security/index.html