CVE-2025-62593
Published Nov 26, 2025
Last updated 3 days ago
AI description
CVE-2025-62593 describes a remote code execution (RCE) vulnerability affecting Ray, an AI compute engine, in versions prior to 2.52.0. The flaw lies in Ray's HTTP API endpoint handling, where an insufficient defense mechanism relies solely on the User-Agent header starting with "Mozilla". This defense is inadequate because the fetch specification allows for the manipulation of the User-Agent header. This vulnerability can be exploited when a developer running Ray visits a malicious website in a vulnerable browser, such as Firefox or Safari. The attack combines the User-Agent bypass with a DNS rebinding attack, tricking the browser into treating a remote attacker-controlled server and the local Ray instance as the same origin. This allows an attacker to trigger arbitrary code execution on the developer's system. The issue has been addressed in Ray version 2.52.0.
- Description
- Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- ray
CVSS 4.0
- Type
- Secondary
- Base score
- 9.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- Ray-Project Ray Code Injection Vulnerability
- Exploit added on
- Aug 17, 2026
- Exploit action due
- Aug 20, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- security-advisories@github.com
- CWE-94
- Hype score
- Not currently trending
🚨 CVE-2025-62593 - critical 🚨 Ray < 2.52.0 - Remote Code Execution > Ray versions prior to 2.52.0 allow unauthenticated remote code execution via the job ... 👾 https://t.co/wM0JpfxoGL @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
24 Sept 2026
512 Impressions
5 Retweets
16 Likes
5 Bookmarks
0 Replies
0 Quotes
Defending Distributed AI Environments Against Active Exploitation of the Ray Code Injection Vulnerability (CVE-2025-62593) https://t.co/9lvVtVFX2Z
@suvobgd
7 Sept 2026
53 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
TeamPCP (G1056) is shifting from ransomware to CI/CD supply chain attacks. They're using worm-driven credential theft. Monitor for T1589.001 and T1592.002, especially if you're in finance, energy, or automotive. Check for activity related to CVE-2025-62593 and CVE-2026-33634.
@BytesNora
6 Sept 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
FirefoxかSafariで不正なページを開くと開発用の端末で任意コード実行に至るRayの脆弱性が、実際の悪用を理由にKEVカタログへ追加されました。対象はCVE-2025-62593で、修正済みの版はRay-2.52.0です。防御はブラウザ
@MalwareBibleJP
28 Aug 2026
885 Impressions
1 Retweet
5 Likes
0 Bookmarks
0 Replies
0 Quotes
🔴 Ray, Remote Code Execution, #CVE-2025-62593 (Critical) -DC-Aug2026-1986 https://t.co/gL9pfzBN6C
@dailycve
28 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV 警告 26/08/17:Ray-Project の脆弱性 CVE-2025-62593 を登録 https://t.co/sGhhdMMN6s AI 開発で広く活用される分散処理フレームワークである、Ray Project の Ray における深刻な脆弱性が、CISA KEV カタログに追加されました
@iototsecnews
27 Aug 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 URGENT: CISA orders a three-day patch after a flaw in the Ray AI framework comes under active attack! CISA has issued an urgent three-day patch order for a code-injection flaw (CVE-2025-62593) in the open-source Ray AI framework, which is currently under active attack. A ht
@Cloudwithchin
25 Aug 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Defending Distributed AI Environments Against Active Exploitation of the Ray Code Injection Vulnerability (CVE-2025-62593) https://t.co/9lvVtVFX2Z
@suvobgd
24 Aug 2026
39 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
CISA directs federal civilian agencies to remediate a CVSS 9.4 code injection vulnerability in Ray-Project Ray. Info, incl. fix info, now at SecAlerts: CVE-2025-62593 - https://t.co/RSPFRIcOGM #ciso #cio #cto #vulnerabilities #cybersecurity #msp #mssp #secalerts #CVE202562593
@SecAlertsCo
24 Aug 2026
156 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-62593 (CVSS 9.4) — Ray framework is being actively exploited. DNS rebinding → arbitrary code execution on developer machines. Botnet was exploiting it before the CVE even dropped. If your team uses Ray: upgrade to 2.52.0 today. 🔗 https://t.co/9RvhmXjLir ht
@aratech_social
23 Aug 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ray CVE-2025-62593 (CVSS 9.4) is RCE via DNS rebinding against a local Ray dashboard. CISA added it to KEV on Aug 17 with a 3-day patch deadline. Open-source AI frameworks on laptops need the same scrutiny as servers. Patch to Ray 2.52.0.
@kysstalol
23 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAが8月17日、AI基盤RayのCVE-2025-62593を悪用確認済みとして登録した 是正期限は8月20日で猶予は3日 User-Agent判定の穴とDNSリバインディングで、開発者がサイトを開くだけで任意コード実行に至る 修正は2.52.0 http
@crafaio
22 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NOOR Threat Feed Brief Here are the summarized CVEs, prioritized by real-world exploitation risk: 1. **CVE-2026-33824 (High Risk)**: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - allows remote code execution. 2. **CVE-2025-62593 (High
@noorchronicle
21 Aug 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISAがRayフレームワークの実悪用中の欠陥CVE-2025-62593をKEVに追加、ブラウザ経由DNSリバインディングでRCEに至るとのこと。AI/ML基盤の外向き露出見直しが要所です。 https://t.co/rHoU3zBmT9 #機械学習
@dejital_secure
20 Aug 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
if Ray is anywhere in your agent stack, patch now. critical remote code execution bug, CVE-2025-62593, federal deadline was today. this is the unglamorous stuff that actually gets founders hacked, not the flashy model releases.
@UnnatBak
20 Aug 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA confirma explotación activa de CVE-2025-62593 (CVSS 9,4) en Ray, el framework de cómputo distribuido de IA con 500M+ descargas. Bypass de User-Agent + DNS rebinding = ejecución de código con solo cargar una web. Parche: Ray 2.52.0. https://t.co/h6njoWSX0a
@BugtraqSolution
20 Aug 2026
92 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
A browser can become the bridge into your AI compute plane. CISA has added CVE-2025-62593 in Ray to its Known Exploited Vulnerabilities catalog after confirmed exploitation. The attack path uses DNS rebinding to reach an otherwise inaccessible Ray interface and turn that access
@ThreatLoom
20 Aug 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA KEV: Ray CVE-2025-62593 (due Aug 20). Local Ray devs face RCE via Firefox/Safari DNS rebinding on unauth Jobs APIs. Patch to 2.52.0+; inventory ML workstations; do not expose the dashboard. https://t.co/f4SaIaCNcG #CISA #CVE
@snypet86
19 Aug 2026
31 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇
@exploitgrid
19 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-62593 in Ray is actively exploited and CISA KEV-listed. A DNS rebinding and User-Agent bypass chain lets a malicious webpage submit jobs to a local Ray Dashboard, achieving RCE without credentials. Key findings: - CVE-2025-62593 (CVSS 4.0: 9.4 Critical, CVSS 3.1: 8.8 h
@DFIR_Radar
19 Aug 2026
136 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2025-62593 was just added to CISA's Known Exploited Vulnerabilities catalog. Affects: Ray-Project Ray. Ray-Project Ray Code Injection Vulnerability. If you run this, patch now, not later. https://t.co/w1s9pthQ0O
@intellibreach
19 Aug 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
แจ้งเตือนช่องโหว่ความรุนแรงสูงในระบบ Ray ถูกนำไปใช้โจมตีจริง เสี่ยงถูกสั่งรันโค้ด ศูนย์ประสานการร
@ThaiCERTByNCSA
19 Aug 2026
71 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA gave 3 days to patch Ray (CVE-2025-62593, due Aug 20). The 2.52.0 fix blocks browser POSTs via Sec-Fetch headers. A curl from your own VPC still submits a job. Token auth ships OFF, and the CVSS 10.0 filed against that default was rejected by NVD. https://t.co/Gy45nvSm2Y
@rajeshberi
19 Aug 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA put Ray Dashboard CVE-2025-62593 on KEV with a 3-day federal clock. The "auth" check is a Mozilla User-Agent string. DNS rebinding plus a Firefox/Safari visit equals RCE on exposed clusters. If Ray is reachable from the network, that is not a research issue. It is an
@cyberogz
19 Aug 2026
54 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/3 CISA just confirmed attackers are actively exploiting a Ray flaw that turns a web page visit into remote code execution. CVE-2025-62593 (CVSS 9.4) hits an AI compute framework used by thousands. Exposed? #CyberSecurity #ZeroDay #Tesla
@CyberTLDR
19 Aug 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
📢 CISA alerte sur l’exploitation active de la faille critique Ray CVE-2025-62593 : correction urgente avant le 20 août 2026. #zoneantimalware https://t.co/tUV9YN51vr
@NicolasCoolman
19 Aug 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA gave federal agencies 3 days to patch CVE-2025-62593. Not 3 weeks. Why: Ray's dashboard treats a "Mozilla" User-Agent string as a security check, trivial to fake. Combine that with DNS rebinding and a malicious webpage gets RCE on any exposed Ray instance. https://t.co/uppDR
@SynScanNet
19 Aug 2026
11 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️⚠️ CVE-2025-62593 (CVSS 9.4, KEV): Unauthenticated server-side RCE on exposed Ray Dashboards, reachable via DNS rebinding in Firefox/Safari. 🔗FOFA Link: https://t.co/OoCE1xD233 🎯1M+ Results are found on https://t.co/pb16tGYaKe. FOFA Query: app="Ray-Dashboard" 🔖
@fofabot
19 Aug 2026
3417 Impressions
9 Retweets
29 Likes
6 Bookmarks
1 Reply
0 Quotes
CISA adds CVE-2025-62593, a code injection vulnerability in Ray-Project Ray that permits remote code execution, to the Known Exploited Vulnerabilities catalog because it is under active exploitation. https://t.co/Z8RZ3KzSIp
@thecircuitry_
19 Aug 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA just gave U.S. federal agencies only three days to patch a critical vulnerability in the Ray AI framework. The flaw (CVE-2025-62593) allows remote code execution and is already under active exploitation. Ray is one of the most widely used open-source systems for scaling AI h
@Aivexbl
18 Aug 2026
33 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
AI基盤の足元からRCE、これは笑えない。 CISAは8月17日、Python-nativeの分散処理フレームワーク「Ray」のCVE-2025-62593を、実悪用の証拠があるとしてKEVへ追加した。ブラウザ経由でRCEにつながり得るcode injectionだ。
@connect24h
18 Aug 2026
439 Impressions
0 Retweets
5 Likes
2 Bookmarks
0 Replies
0 Quotes
CVSS 9.4が1本ある。国内大手2社のデータが漏れ、AIがAIを攻撃した。 開発環境もAIツールも、今から君が守るものだ。 ・Ray CVE-2025-62593(CVSS 9.4)、AI開発基盤にブラウザ経由RCE——KEV追加 ・日本交通に2.9TB窃取
@boss_sec_labo
18 Aug 2026
1628 Impressions
1 Retweet
18 Likes
9 Bookmarks
0 Replies
0 Quotes
CVE-2025-62593: CISA Flags Ray RCE, Update to 2.52.0 CISA has added CVE-2025-62593, a critical remote-code-execution flaw in the Ray distributed AI framework, to its Known Exploited Vulnerabilities catalog after changing its assessment from proof-of-concept availability to
@VistemSolutions
18 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-of-the-Day: CVE-2025-62593 — Ray AI compute engine, Remote Code Execution (RCE) via browser + DNS rebinding CVSS: 9.4 | EPSS: 0.4% A developer simply visiting a malicious website in Firefox or Safari can have their own browser silently reach into their local Ray inst
@YourDailyCVE
18 Aug 2026
22 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
TRC analysis shows attackers exploiting CVE-2025-62593 in Ray AI systems via DNS rebinding to achieve remote code execution on developer machines. Post-compromise activity includes privilege escalation and lateral network movement. Runtime segmentation helps limit blast radius in
@aviatrixtrc
18 Aug 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ray GHSA for CVE-2025-62593 (CVSS 9.4): maintainers call missing auth on /api/jobs a "longstanding decision." DNS rebinding + User-Agent rewrite → RCE on local Ray via Firefox/Safari; browser can confused-deputy to adjacent corp instances. Chrome out of path (Chromium blocks th
@beuchelt
18 Aug 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
localhost にしか bind していないから安全、が通じない話。Ray CVE-2025-62593 の仕組みを DNS リバインディングから読み解いて、venv を横断して該当バージョンを洗い出す依存なしの判定スクリプトまで書きました。
@Joe_Biden_ja
18 Aug 2026
367 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
1 Quote
43,500+ GitHub stars. That's Ray's reach - and CISA just confirmed active exploitation, adding it to KEV. CVE-2025-62593 (CVSS 9.4): unauthenticated API endpoints let a malicious site trigger DNS rebinding into browser-based RCE. https://t.co/A8n0pvR6TL #InfoSec #ThreatIntel
@Deepcyber_io
18 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
1/4 🚨 24h Cyber Alert – Aug 18 CISA just dropped a new KEV + flagged a Windows flaw as ransomware-used. Ray RCE. Task Host → SYSTEM. WMIC killed. Azure dumps for sale. Cl0p back. This is the one you save. Full breakdown + actions ↓ 2/4 New KEV: CVE-2025-62593 – Ray (AI
@seoscottsdale
18 Aug 2026
236 Impressions
2 Retweets
0 Likes
0 Bookmarks
3 Replies
0 Quotes
🚨 CISA Confirms Active Exploitation of Critical Ray AI Framework Vulnerability CISA has added **CVE-2025-62593**, a critical code-injection vulnerability affecting the Ray distributed computing framework, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming h
@DailyDarkWeb
18 Aug 2026
6060 Impressions
4 Retweets
21 Likes
6 Bookmarks
1 Reply
0 Quotes
NewNormal Security turns the last 24 hours of CVEs into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 18 Aug 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 🖥️ Unauthenticated cluster dashboard — submit a job and the
@NewScanTeam
18 Aug 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: Critical code injection in #RayAI CVE-2025-62593 CVSS: 9.4. It was added to the #CISA #KEV list yesterday as it is actively-exploited #Patch #Patch #Patch
@CCBalert
18 Aug 2026
232 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA just put Ray CVE-2025-62593 on the KEV list. Browser DNS-rebinding RCE on anything before 2.52.0, Firefox and Safari, no login. Federal clock is Thursday. That's what fans jobs across GPU nodes. Checking the Spark boxes tonight. https://t.co/4b6TT6aMn6
@StevenKNH
18 Aug 2026
29 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔐 UNITED STATES: CISA issues emergency directive requiring federal agencies to patch critical code-injection vulnerability in Ray AI framework (CVE-2025-62593) by August 20. Active exploitation confirmed; vulnerability added to Known Exploited Vulnerabilities catalogue. https:
@threatwhere
18 Aug 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
CISA KEV ALERT: CVE-2025-62593 (CVSS 9.4) in Ray 200,000 clusters open to pre-auth RCE. Federal patch deadline: August 20. ShadowRay 2.0 is mining NVIDIA A100s and stealing model weights. Patch: Ray 2.52.0. Block 8265/8266. Hunt kworker/0:0. #CVE202562593 #RayRCE #CISAAlert h
@DecryptionDigst
18 Aug 2026
26 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 URGENTE: CISA advierte sobre vulnerabilidad crítica en IA Ray 🚨 La falla CVE-2025-62593 permite ejecución remota de código. Agencias federales tienen solo 3 días para parchear o desconectar el software. La vulnerabilidad ya está siendo explotada activamente.
@DiarioBitcoin
18 Aug 2026
740 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡️ CYBER BULLETIN | 2026/08/18 🚨 1. CISA adds critical Ray RCE to KEV catalog CISA flagged CVE-2025-62593 (CVSS 9.4) in the popular open-source Ray AI/ML framework as actively exploited. The flaw enables browser-based remote code execution via DNS rebinding on Firefox an
@FrontieraTechIT
18 Aug 2026
139 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
UN ANUNCIO = RCE en Ray (CVE-2025-62593) #byte_shield #ciberseguridad #newsfeed #hacker #cisa https://t.co/q5T0jE8QqJ
@GallegoWil81171
18 Aug 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added Ray CVE-2025-62593 to KEV, confirming exploitation. If Ray <2.52.0 exists anywhere—including developer laptops—upgrade, enable token auth, restrict TCP/8265, and review job submissions. Deadline: Aug. 20. https://t.co/BPxKaADIp2
@isectech_
18 Aug 2026
19 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Running Ray for your ML pipelines? 🚨 CVE-2025-62593 puts your entire AI cluster at risk of Remote Code Execution. See how to isolate and patch your framework today: https://t.co/cKzQVn7LNo #CyberSecurity #cybernews #latestupdates #newsfile
@CyberUpdates365
18 Aug 2026
21 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EEAA235D-B305-4247-8840-CCABC90D54C1",
"versionEndExcluding": "2.52.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]