PT-2025-48198 · Anyscale · Ray
Published
2025-11-14
·
Updated
2026-03-11
·
CVE-2025-62593
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ray versions prior to 2.52.0
Description
Ray, an AI compute engine, is affected by a critical Remote Code Execution (RCE) issue. The problem stems from insufficient protection against browser-based attacks. The current defense relies on the
User-Agent header, specifically checking for the string "Mozilla," but the fetch specification allows modification of this header. This, combined with a DNS rebinding attack, allows an attacker to execute arbitrary code through the browsers Firefox and Safari. A developer running Ray could be exploited by visiting a malicious website or being served a malicious advertisement (malvertising). Approximately 2,100 vulnerable instances have been identified. The issue is exploitable against developers using Ray as a development tool. The vulnerability is triggered through a DNS rebinding attack.Recommendations
Update to Ray version 2.52.0 or later.
Exploit
Fix
RCE
CSRF
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ray