Remote Code Execution Vulnerability in Ray AI Compute Engine
CVE-2025-62593
9.4CRITICAL
What is CVE-2025-62593?
Ray AI Compute Engine, widely utilized as a development tool, contains a significant RCE vulnerability in versions prior to 2.52.0. This vulnerability arises from a failure to properly safeguard against browser-based attacks. The existing defense mechanism inadequately relies on the User-Agent header, which can easily be manipulated according to the fetch specification. As a result, developers using Ray could be exploited through a malicious website visit or harmful advertisements, particularly when using browsers like Firefox and Safari. It is recommended to upgrade to version 2.52.0 or newer to mitigate these security risks.
Affected Version(s)
ray < 2.52.0
