Ray-Project Ray npm Package: Code Injection Vulnerability Warning
- Severity
- HIGH
- Affected component
- ray-project ray (npm)
- Affected versions
- >= ray-0.7.0, <= ray-0.7.0 or >= ray-0.6.5, <= ray-0.6.5 or >= ray-0.6.4, <= ray-0.6.4 or >= ray-0.6.3, <= ray-0.6.3 or >= ray-0.6.2, <= ray-0.6.2 or >= ray-0.6.1, <= ray-0.6.1 or >= ray-0.6.0, <= ray-0.6.0 or >= ray-0.5.3, <= ray-0.5.3 or >= ray-0.5.2, <= ray-0.5.2 or >= ray-0.5.1, <= ray-0.5.1 or >= ray-0.5.0, <= ray-0.5.0 or >= ray-0.4.0, <= ray-0.4.0 or >= ray-0.3.1, <= ray-0.3.1 or >= ray-0.3.0, <= ray-0.3.0 or >= ray-0.2.2, <= ray-0.2.2 or >= ray-0.2.1, <= ray-0.2.1 or >= ray-0.2.0, <= ray-0.2.0 or >= ray-0.1.2, <= ray-0.1.2 or >= ray-0.1.1, <= ray-0.1.1 or >= ray-0.1.0, <= ray-0.1.0
- Patched version
- Not yet available
An early warning has been issued for a code injection vulnerability in the Ray-Project Ray npm package. Developers using Ray may be at risk.
What happened
The Ray-Project Ray npm package reportedly contains a code injection vulnerability that could allow remote code execution. This vulnerability is exploitable through Firefox and Safari. The package versions affected range from ray-0.1.0 to ray-0.7.0 inclusive. The exploit is under investigation and has been flagged as being used in the wild.
Developers who have incorporated Ray into their development workflow should assess their exposure to this vulnerability. The exploit mechanism involves the injection of malicious code which could be executed remotely under certain conditions.
What to do about it
- Upgrade to the latest version of Ray-Project Ray to mitigate potential exposure.
- Monitor your development and production environments for any suspicious activity that may indicate exploitation of this vulnerability.
- Consult the primary sources for the most current information and updates on this vulnerability.
How 0Day would have caught this
ray-project ray is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Ray-Project Ray npm package versions from ray-0.1.0 to ray-0.7.0 inclusive, you may be affected.
What should I do right now?
Upgrade to the latest version of Ray-Project Ray and monitor your environments for suspicious activity.
Has this been exploited in the wild?
Yes, this vulnerability appears to have been exploited in the wild.