← All Advisories

CVE-2025-62593: Ray-Project Ray Code

Status: KEV  |  Advisory ID: CVE-2025-62593

Key Details

CVECVE-2025-62593
CVSSCVSS 8.8 (High).
Affected productsRay-Project Ray and anyscale ray
Exploitation statusListed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation.
Classified asCWE-94 (Improper Control of Generation of Code ('Code Injection'))
KEV listingAdded to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-08-17.
Exploitation prediction (EPSS)17% probability of exploitation in the next 30 days (97% percentile) -- FIRST.org's EPSS model.
Federal remediation deadline2026-08-20 (CISA KEV, Binding Operational Directive).

What to Know

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-62593