CVE-2025-62593
Published Nov 26, 2025
Last updated a day ago
AI description
CVE-2025-62593 describes a remote code execution (RCE) vulnerability affecting Ray, an AI compute engine, in versions prior to 2.52.0. The flaw lies in Ray's HTTP API endpoint handling, where an insufficient defense mechanism relies solely on the User-Agent header starting with "Mozilla". This defense is inadequate because the fetch specification allows for the manipulation of the User-Agent header. This vulnerability can be exploited when a developer running Ray visits a malicious website in a vulnerable browser, such as Firefox or Safari. The attack combines the User-Agent bypass with a DNS rebinding attack, tricking the browser into treating a remote attacker-controlled server and the local Ray instance as the same origin. This allows an attacker to trigger arbitrary code execution on the developer's system. The issue has been addressed in Ray version 2.52.0.
- Description
- Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- ray
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Ray-Project Ray Code Injection Vulnerability
- Exploit added on
- Aug 17, 2026
- Exploit action due
- Aug 20, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-94
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
35
CISA gave 3 days to patch Ray (CVE-2025-62593, due Aug 20). The 2.52.0 fix blocks browser POSTs via Sec-Fetch headers. A curl from your own VPC still submits a job. Token auth ships OFF, and the CVSS 10.0 filed against that default was rejected by NVD. https://t.co/Gy45nvSm2Y
@rajeshberi
19 Aug 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA put Ray Dashboard CVE-2025-62593 on KEV with a 3-day federal clock. The "auth" check is a Mozilla User-Agent string. DNS rebinding plus a Firefox/Safari visit equals RCE on exposed clusters. If Ray is reachable from the network, that is not a research issue. It is an
@cyberogz
19 Aug 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/3 CISA just confirmed attackers are actively exploiting a Ray flaw that turns a web page visit into remote code execution. CVE-2025-62593 (CVSS 9.4) hits an AI compute framework used by thousands. Exposed? #CyberSecurity #ZeroDay #Tesla
@CyberTLDR
19 Aug 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
📢 CISA alerte sur l’exploitation active de la faille critique Ray CVE-2025-62593 : correction urgente avant le 20 août 2026. #zoneantimalware https://t.co/tUV9YN51vr
@NicolasCoolman
19 Aug 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA gave federal agencies 3 days to patch CVE-2025-62593. Not 3 weeks. Why: Ray's dashboard treats a "Mozilla" User-Agent string as a security check, trivial to fake. Combine that with DNS rebinding and a malicious webpage gets RCE on any exposed Ray instance. https://t.co/uppDR
@SynScanNet
19 Aug 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️⚠️ CVE-2025-62593 (CVSS 9.4, KEV): Unauthenticated server-side RCE on exposed Ray Dashboards, reachable via DNS rebinding in Firefox/Safari. 🔗FOFA Link: https://t.co/OoCE1xD233 🎯1M+ Results are found on https://t.co/pb16tGYaKe. FOFA Query: app="Ray-Dashboard" 🔖
@fofabot
19 Aug 2026
1257 Impressions
7 Retweets
16 Likes
3 Bookmarks
0 Replies
0 Quotes
CISA adds CVE-2025-62593, a code injection vulnerability in Ray-Project Ray that permits remote code execution, to the Known Exploited Vulnerabilities catalog because it is under active exploitation. https://t.co/Z8RZ3KzSIp
@thecircuitry_
19 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA just gave U.S. federal agencies only three days to patch a critical vulnerability in the Ray AI framework. The flaw (CVE-2025-62593) allows remote code execution and is already under active exploitation. Ray is one of the most widely used open-source systems for scaling AI h
@Aivexbl
18 Aug 2026
21 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
AI基盤の足元からRCE、これは笑えない。 CISAは8月17日、Python-nativeの分散処理フレームワーク「Ray」のCVE-2025-62593を、実悪用の証拠があるとしてKEVへ追加した。ブラウザ経由でRCEにつながり得るcode injectionだ。
@connect24h
18 Aug 2026
367 Impressions
0 Retweets
5 Likes
2 Bookmarks
0 Replies
0 Quotes
CVSS 9.4が1本ある。国内大手2社のデータが漏れ、AIがAIを攻撃した。 開発環境もAIツールも、今から君が守るものだ。 ・Ray CVE-2025-62593(CVSS 9.4)、AI開発基盤にブラウザ経由RCE——KEV追加 ・日本交通に2.9TB窃取
@boss_sec_labo
18 Aug 2026
1218 Impressions
1 Retweet
11 Likes
5 Bookmarks
0 Replies
0 Quotes
CVE-2025-62593: CISA Flags Ray RCE, Update to 2.52.0 CISA has added CVE-2025-62593, a critical remote-code-execution flaw in the Ray distributed AI framework, to its Known Exploited Vulnerabilities catalog after changing its assessment from proof-of-concept availability to
@VistemSolutions
18 Aug 2026
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2025-62593 — Ray AI compute engine, Remote Code Execution (RCE) via browser + DNS rebinding CVSS: 9.4 | EPSS: 0.4% A developer simply visiting a malicious website in Firefox or Safari can have their own browser silently reach into their local Ray inst
@YourDailyCVE
18 Aug 2026
21 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
TRC analysis shows attackers exploiting CVE-2025-62593 in Ray AI systems via DNS rebinding to achieve remote code execution on developer machines. Post-compromise activity includes privilege escalation and lateral network movement. Runtime segmentation helps limit blast radius in
@aviatrixtrc
18 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ray GHSA for CVE-2025-62593 (CVSS 9.4): maintainers call missing auth on /api/jobs a "longstanding decision." DNS rebinding + User-Agent rewrite → RCE on local Ray via Firefox/Safari; browser can confused-deputy to adjacent corp instances. Chrome out of path (Chromium blocks th
@beuchelt
18 Aug 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
localhost にしか bind していないから安全、が通じない話。Ray CVE-2025-62593 の仕組みを DNS リバインディングから読み解いて、venv を横断して該当バージョンを洗い出す依存なしの判定スクリプトまで書きました。
@Joe_Biden_ja
18 Aug 2026
355 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
1 Quote
43,500+ GitHub stars. That's Ray's reach - and CISA just confirmed active exploitation, adding it to KEV. CVE-2025-62593 (CVSS 9.4): unauthenticated API endpoints let a malicious site trigger DNS rebinding into browser-based RCE. https://t.co/A8n0pvR6TL #InfoSec #ThreatIntel
@Deepcyber_io
18 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/4 🚨 24h Cyber Alert – Aug 18 CISA just dropped a new KEV + flagged a Windows flaw as ransomware-used. Ray RCE. Task Host → SYSTEM. WMIC killed. Azure dumps for sale. Cl0p back. This is the one you save. Full breakdown + actions ↓ 2/4 New KEV: CVE-2025-62593 – Ray (AI
@seoscottsdale
18 Aug 2026
220 Impressions
2 Retweets
0 Likes
0 Bookmarks
3 Replies
0 Quotes
🚨 CISA Confirms Active Exploitation of Critical Ray AI Framework Vulnerability CISA has added **CVE-2025-62593**, a critical code-injection vulnerability affecting the Ray distributed computing framework, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming h
@DailyDarkWeb
18 Aug 2026
5572 Impressions
3 Retweets
17 Likes
6 Bookmarks
1 Reply
0 Quotes
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 18 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated cluster dashboard — submit a job and the
@NewScanTeam
18 Aug 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: Critical code injection in #RayAI CVE-2025-62593 CVSS: 9.4. It was added to the #CISA #KEV list yesterday as it is actively-exploited #Patch #Patch #Patch
@CCBalert
18 Aug 2026
223 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA just put Ray CVE-2025-62593 on the KEV list. Browser DNS-rebinding RCE on anything before 2.52.0, Firefox and Safari, no login. Federal clock is Thursday. That's what fans jobs across GPU nodes. Checking the Spark boxes tonight. https://t.co/4b6TT6aMn6
@StevenKNH
18 Aug 2026
27 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔐 UNITED STATES: CISA issues emergency directive requiring federal agencies to patch critical code-injection vulnerability in Ray AI framework (CVE-2025-62593) by August 20. Active exploitation confirmed; vulnerability added to Known Exploited Vulnerabilities catalogue. https:
@threatwhere
18 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CISA KEV ALERT: CVE-2025-62593 (CVSS 9.4) in Ray 200,000 clusters open to pre-auth RCE. Federal patch deadline: August 20. ShadowRay 2.0 is mining NVIDIA A100s and stealing model weights. Patch: Ray 2.52.0. Block 8265/8266. Hunt kworker/0:0. #CVE202562593 #RayRCE #CISAAlert h
@DecryptionDigst
18 Aug 2026
25 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 URGENTE: CISA advierte sobre vulnerabilidad crítica en IA Ray 🚨 La falla CVE-2025-62593 permite ejecución remota de código. Agencias federales tienen solo 3 días para parchear o desconectar el software. La vulnerabilidad ya está siendo explotada activamente.
@DiarioBitcoin
18 Aug 2026
734 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️ CYBER BULLETIN | 2026/08/18 🚨 1. CISA adds critical Ray RCE to KEV catalog CISA flagged CVE-2025-62593 (CVSS 9.4) in the popular open-source Ray AI/ML framework as actively exploited. The flaw enables browser-based remote code execution via DNS rebinding on Firefox an
@FrontieraTechIT
18 Aug 2026
134 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
UN ANUNCIO = RCE en Ray (CVE-2025-62593) #byte_shield #ciberseguridad #newsfeed #hacker #cisa https://t.co/q5T0jE8QqJ
@GallegoWil81171
18 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added Ray CVE-2025-62593 to KEV, confirming exploitation. If Ray <2.52.0 exists anywhere—including developer laptops—upgrade, enable token auth, restrict TCP/8265, and review job submissions. Deadline: Aug. 20. https://t.co/BPxKaADIp2
@isectech_
18 Aug 2026
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Running Ray for your ML pipelines? 🚨 CVE-2025-62593 puts your entire AI cluster at risk of Remote Code Execution. See how to isolate and patch your framework today: https://t.co/cKzQVn7LNo #CyberSecurity #cybernews #latestupdates #newsfile
@CyberUpdates365
18 Aug 2026
21 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Is your AI infrastructure exposed? 🛑 A critical vulnerability (CVE-2025-62593) in the Ray AI framework allows attackers to hijack machine learning clusters. Secure your workloads: https://t.co/OWH3WhHOFn #AI #MLOps #CVE202562593 #technews
@secureblognews
18 Aug 2026
30 Impressions
0 Retweets
3 Likes
0 Bookmarks
0 Replies
0 Quotes
CyberSec Daily ✓ · 🚨 Active Exploitation · August 18, 2026 🎯 CISA flags critical Ray AI-framework vulnerability as actively exploited CISA has added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog after confirming real-world exploitation. The vulnerabil
@XQOPTRX
18 Aug 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA has flagged Ray's CVE-2025-62593 as actively exploited, urging developers to update to version 2.52.0 to prevent remote code execution via DNS rebinding attacks. #Cybersecurity #Ray #CVE202562593 #RemoteCodeExecution #DNSRebinding #CISA #SecurityUpdate https://t.co/0yYvbcyo
@dailytechonx
18 Aug 2026
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ An actively exploited Ray flaw can lead to browser-based RCE. CISA has added CVE-2025-62593 to its KEV catalog. The documented attack path uses DNS rebinding and requires a developer running Ray to visit a malicious site or be served a malicious ad in Firefox or Safari.
@TheHackersNews
18 Aug 2026
28916 Impressions
22 Retweets
95 Likes
18 Bookmarks
9 Replies
0 Quotes
CISA adds Ray framework CVE-2025-62593 to KEV after confirmed in-the-wild exploitation. The critical RCE flaw affects Firefox and Safari; DNS rebinding can lead to code injection when malicious ads are rendered. Fixed in Ray 2.52.0 with CVSS 9.4. #ThreatIntel #CVE #Ray
@WorldCyberNewsX
18 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Aug 17) CVE-2025-62593 Ray-Project Ray コードインジェクションの脆弱性 https://t.co/d08WpetvKY
@foxbook
18 Aug 2026
212 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-62593 στο Ray: Κρίσιμη RCE σε πλατφόρμες τεχνητής νοημοσύνης https://t.co/jxXjmek78o
@SecNews_GR
18 Aug 2026
142 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-08-17 CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability CVSS 9.4 · EPSS 0.4% · 4 public exploits Details, versions & intel → https://t.co/WrjoNswVms https://t.co/kDn0hIkc0M
@notCVE
18 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Aug 17) CVE-2025-62593--Ray-Project Ray Code: patch Ray-Project Ray Code and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/4aW0CIkxua
@PCMedicalist
18 Aug 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2025-62593: Ray Code Injection Vulnerability Actively Exploited — Detection… "On August 17, 2026, CISA added CVE-2025-62593 — a code injection vulnerability in the Ray…" 🔗 https://t.co/k7Cr9J5z9M #CyberSecurity #ThreatIntel #cve #zeroday #pa
@SecurityAr58409
18 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/7 CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog. The critical Ray flaw can turn a malicious web page into code execution on a developer's Ray node. Affected: Ray < 2.52.0. Fixed: 2.52.0+. https://t.co/UhBz1IFB8W
@SOCMinute
18 Aug 2026
11 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CISA、AIフレームワーク「Ray」の悪用中脆弱性(CVE-2025-62593)をKEVに追加 — Firefox/Safari経由で開発者のPCに任意コード実行、修正版2.52.0で対応 https://t.co/nGFoGOZPBD
@NEXSIGHTNEWS
18 Aug 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ray の RCE 脆弱性 CVE-2025-62593 が CISA KEV に追加されました。 ・影響範囲は Ray 2.52.0 未満 ・DNS rebinding で localhost の Ray も対象 ・Firefox / Safari 利用が攻撃条件 https://t.co/scRyLTpPsY #Ray
@MyTechBlogJP
17 Aug 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに、Ray(分散実行基盤)のコマンドインジェクションCVE-2025-62593を追加。対処期限は3日後の8/20。ランサムウェアによる
@__kokumoto
17 Aug 2026
655 Impressions
0 Retweets
2 Likes
2 Bookmarks
1 Reply
0 Quotes
米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/17追加) #vulnerability 🛡CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability ✅概要 ・深刻度:緊急 9.4 (CVSS Base) / GitHub (CNA) ・種別:コード・イン
@piyokango
17 Aug 2026
5201 Impressions
3 Retweets
8 Likes
2 Bookmarks
0 Replies
0 Quotes
CVE-2025-62593: Ray RCE Exploited in the Wild - https://t.co/cHhn6wDeaQ
@moton
17 Aug 2026
273 Impressions
0 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
Cyber Heat Radar|2026/08/18 05:00 JST 今回は①17th August 脅威インテリジェンス報告の件、②CVE-2025-62593 CISA KEV追加の件、③Microsoft Defender ShieldBreak…の件を中心に、ほか4件を含めて音声で7件扱います。
@cyberheatradar
17 Aug 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️We added CVE-2025-62593, a critical code injection #RCE vulnerability affecting Ray-Project Ray, to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/hcKeyl36te
@CISACyber
17 Aug 2026
7382 Impressions
6 Retweets
18 Likes
4 Bookmarks
1 Reply
0 Quotes
🔒 #CyberSecurity CVE-2025-62593: Ray Code Injection Vulnerability Under Active Exploitation — CI… "On August 18, 2026, CISA formally added CVE-2025-62593 — a code injection…" 🔗 https://t.co/fQeExgIV22 #CyberSecurity #ThreatIntel #cve202562593 #critical #cisakev
@SecurityAr58409
17 Aug 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-62593: Cross-Site Code Injection Risk in Ray AI Framework CVE-2025-62593 allows attackers to execute arbitrary code in Ray-Project Ray via browser-based CSRF attacks in Firefox and Safari. Full write-up → link in bio #cybersecurity #infosec #cve #kev #RayProject http
@HotaSamit
17 Aug 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers exploiting CVE-2025-62593 in Ray AI compute engine through DNS rebinding to achieve remote code execution. Post-compromise chains include privilege escalation and lateral movement across developer infrastructure. Runtime segmentation helps contain
@aviatrixtrc
17 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA confirms CVE-2025-62593, a critical Ray remote code execution flaw, is exploited in the wild. A public PoC targets Firefox and Safari. #CVE202562593 #Ray #RemoteCodeExecution #DNSRebinding #KEV #ExploitedInTheWild https://t.co/ubBx6LZ3qX
@Daily_CyberSec
17 Aug 2026
393 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EEAA235D-B305-4247-8840-CCABC90D54C1",
"versionEndExcluding": "2.52.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]