Remote Code Execution Vulnerability in Ray AI Compute Engine
CVE-2025-62593

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
26 November 2025

Badges

📈 Score: 446👾 Exploit Exists🟡 Public PoC🟣 EPSS 16%🦅 CISA Reported📰 News Worthy

What is CVE-2025-62593?

CVE-2025-62593 is a critical remote code execution vulnerability in Ray, an AI compute engine that facilitates distributed applications and enhances machine learning workflows. This vulnerability affects versions of Ray prior to 2.52.0 and stems from inadequate defense mechanisms against browser-based attacks. Specifically, the vulnerability exploits the User-Agent header handling, which is insufficient given that attackers can manipulate this header due to the fetch specification. When a developer using Ray inadvertently visits a malicious site or interacts with compromised advertisements, they become vulnerable to a DNS rebinding attack, allowing an attacker to execute arbitrary code on their development setup. This could lead to unauthorized access and significant operational disruptions for organizations relying on Ray for AI and machine learning tasks.

Potential impact of CVE-2025-62593

  1. Unauthorized Remote Code Execution: The vulnerability enables attackers to execute arbitrary code on systems running vulnerable versions of Ray, potentially leading to unauthorized access to sensitive data and system takeover.

  2. Disruption of AI Development Workflows: An exploit could compromise the integrity of ongoing AI projects, leading to data loss, corruption, or tampering, which could significantly hinder an organization’s technological advancements and disrupt development timelines.

  3. Increased Risk of Further Attacks: Successful exploitation could allow attackers to implant persistent backdoors or malware within the compromised systems, enabling not only data breaches but also the potential for lateral movement to other systems within the organization’s network.

CISA has reported CVE-2025-62593

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2025-62593 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

ray < 2.52.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

CISA adds actively exploited Ray flaw CVE-2025-62593 to KEV; DNS rebinding can trigger browser-based RCE on developer systems.

2 weeks ago

References

EPSS Score

16% chance of being exploited in the next 30 days.

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 📰

    First article discovered by The Hacker News

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.