CISA Warns of Ray-Project Ray Code Injection Vulnerability Exploited in Attacks
Brief
CISA has added a critical Ray-Project Ray vulnerability, tracked as CVE-2025-62593 , to its Known Exploited Vulnerabilities catalog after confirming exploitation in the wild. The flaw can allow remote code execution on systems where vulnerable Ray development environments are running.
Ray is an open-source distributed computing framework widely used by Python developers and AI teams for scaling machine learning, data processing, and application workloads.
The issue affects Ray versions before 2.
- 0 and is especially dangerous for developers using Firefox or Safari. At the same time, Ray is active on their local workstation or development server. The Ray Project addressed the vulnerability in version 2.
- 0.
CVE-2025-62593 stems from insufficient protections for Ray HTTP API endpoints, including job-related endpoints that can accept requests that can launch code.
