VMTech
Discuss a project

CISA lists actively exploited Ray browser-based RCE vulnerability

CISA lists actively exploited Ray browser-based RCE vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2025-62593, a critical vulnerability in the Ray distributed computing framework, to its Known Exploited Vulnerabilities catalog after finding evidence of active exploitation. The flaw has a CVSS score of 9.4 and can enable remote code execution through Mozilla Firefox and Apple Safari using a DNS rebinding attack.

Ray is an open-source, Python-native framework used to scale artificial intelligence and machine-learning workloads. The project has more than 43,500 GitHub stars and more than 7,900 forks. Ray maintainers fixed CVE-2025-62593 in version 2.52.0 of the Python package.

Browser access can become a code-execution path

The vulnerability concerns critical Ray endpoints, including /api/jobs and /api/job_agent/jobs/, which Ray maintainers said lack authentication. The issue arises from insufficient controls against browser-based attacks in cases where an attacker can modify the User-Agent header.

Combined with DNS rebinding, that condition can make a Ray instance accessible to an attacker when a developer running Ray visits a malicious website or receives a malicious advertisement. The maintainers said the primary risk concerns development and testing environments. A successful phishing lure or malicious advertisement could result in arbitrary shell code running on the victim's machine.

The attack can also extend beyond a local developer setup. By using a browser as a confused-deputy intermediary, an attacker may target network-adjacent Ray instances operating within a private corporate network. This browser-mediated exposure fits alongside the risks highlighted in AI attack chains and agent incidents, where attack chains and AI-agent incidents underscored the need to examine interconnected systems.

Active exploitation raises remediation priority

CISA has not released details on the observed exploitation. However, BitSight reported in March 2026 that the operators of the RondoDox DDoS botnet had added the vulnerability to their toolkit two days before its public disclosure on November 26, 2025, after a proof-of-concept exploit became available.

Oligo also said attackers had targeted unpatched Ray deployments in an effort to turn compromised clusters containing NVIDIA GPUs into a self-replicating cryptocurrency-mining botnet called ShadowRay 2.0. Ray credited Oligo researcher Avi Lumelsky with discovering the fetch bypass and Jonathan Leitschuh with devising the DNS rebinding attack.

Federal Civilian Executive Branch agencies are recommended to apply fixes and mitigations by August 20, 2026. For organizations using Ray, the immediate business implication is to inventory development, test, and private-network deployments, upgrade to version 2.52.0, and include browser-driven access paths in remediation planning.

#cybersecurity#vulnerability#raysecurity#remotecodeexecution
Open analytics
On the site 0 views
min read 3 18.08.2026
Instagram

CISA lists actively exploited Ray browser-based RCE vulnerability

Open the post on Instagram ↗