PT-2025-48198 · Anyscale · Ray

CVE-2025-62593

·

Published

2025-11-14

·

Updated

2026-06-29

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Ray versions prior to 2.52.0
Description Ray, an AI compute engine, is affected by a critical Remote Code Execution (RCE) issue. The problem stems from insufficient protection against browser-based attacks. The current defense relies on the User-Agent header, specifically checking for the string "Mozilla," but the fetch specification allows modification of this header. This, combined with a DNS rebinding attack, allows an attacker to execute arbitrary code through the browsers Firefox and Safari. A developer running Ray could be exploited by visiting a malicious website or being served a malicious advertisement (malvertising). Approximately 2,100 vulnerable instances have been identified. The issue is exploitable against developers using Ray as a development tool. The vulnerability is triggered through a DNS rebinding attack.
Recommendations Update to Ray version 2.52.0 or later.

Exploit

Fix

RCE

CSRF

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-14769
CVE-2025-62593
GHSA-Q279-JHRF-CC6V
PYSEC-2026-520

Affected Products

Ray