CVE Details

CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability
Published: 2026-08-18 CVSS: 9.4 CRITICAL Product: Ray-Project Ray Due Date: 2026-08-21

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.

No GitHub PoC data.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.4
  • Severity: CRITICAL
  • Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC

  • Exploitation: poc
  • Automatable: no
  • Technical Impact: total

References

Show Raw Data
Key Remaining Key Value
dataType CVE_RECORD
dataVersion 5.2
cveMetadata > cveId CVE-2025-62593
cveMetadata > assignerOrgId a0819718-46f1-4df5-94e2-005712e83aaa
cveMetadata > state PUBLISHED
cveMetadata > assignerShortName GitHub_M
cveMetadata > dateReserved 2025-10-16T19:24:37.266Z
cveMetadata > datePublished 2025-11-26T22:28:28.577Z
cveMetadata > dateUpdated 2026-08-17T13:31:33.723Z
containers > cna > title Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
containers > cna > problemTypes > 0 > descriptions > 0 > cweId CWE-94
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > description CWE-94: Improper Control of Generation of Code ('Code Injection')
containers > cna > problemTypes > 0 > descriptions > 0 > type CWE
containers > cna > problemTypes > 1 > descriptions > 0 > cweId CWE-352
containers > cna > problemTypes > 1 > descriptions > 0 > lang en
containers > cna > problemTypes > 1 > descriptions > 0 > description CWE-352: Cross-Site Request Forgery (CSRF)
containers > cna > problemTypes > 1 > descriptions > 0 > type CWE
containers > cna > metrics > 0 > cvssV4_0 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV4_0 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV4_0 > attackRequirements NONE
containers > cna > metrics > 0 > cvssV4_0 > privilegesRequired NONE
containers > cna > metrics > 0 > cvssV4_0 > userInteraction PASSIVE
containers > cna > metrics > 0 > cvssV4_0 > vulnConfidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > vulnIntegrityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > vulnAvailabilityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > subConfidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > subIntegrityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > subAvailabilityImpact HIGH
containers > cna > metrics > 0 > cvssV4_0 > baseScore 9.4
containers > cna > metrics > 0 > cvssV4_0 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV4_0 > vectorString CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
containers > cna > metrics > 0 > cvssV4_0 > version 4.0
containers > cna > references > 0 > name https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v
containers > cna > references > 0 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 0 > url https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v
containers > cna > references > 1 > name https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09
containers > cna > references > 1 > tags > 0 x_refsource_MISC
containers > cna > references > 1 > url https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09
containers > cna > affected > 0 > vendor ray-project
containers > cna > affected > 0 > product ray
containers > cna > affected > 0 > versions > 0 > version < 2.52.0
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > providerMetadata > orgId a0819718-46f1-4df5-94e2-005712e83aaa
containers > cna > providerMetadata > shortName GitHub_M
containers > cna > providerMetadata > dateUpdated 2025-11-26T22:28:28.577Z
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
containers > cna > source > advisory GHSA-q279-jhrf-cc6v
containers > cna > source > discovery UNKNOWN
containers > adp > 0 > references > 0 > url https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis
containers > adp > 0 > references > 0 > tags > 0 third-party-advisory
containers > adp > 0 > metrics > 0 > other > type ssvc
containers > adp > 0 > metrics > 0 > other > content > timestamp 2025-11-28T18:21:16.960626Z
containers > adp > 0 > metrics > 0 > other > content > id CVE-2025-62593
containers > adp > 0 > metrics > 0 > other > content > options > 0 > Exploitation poc
containers > adp > 0 > metrics > 0 > other > content > options > 1 > Automatable no
containers > adp > 0 > metrics > 0 > other > content > options > 2 > Technical Impact total
containers > adp > 0 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 0 > metrics > 0 > other > content > version 2.0.3
containers > adp > 0 > title CISA ADP Vulnrichment
containers > adp > 0 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 0 > providerMetadata > shortName CISA-ADP
containers > adp > 0 > providerMetadata > dateUpdated 2026-08-17T13:31:33.723Z