Ray-Project Ray Code Injection Vulnerability
π¨SEVERITY: CRITICAL β CVSS 9.4Security Advisory
TL;DR π
- Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
- Highest CVSS: 9.4 (Critical).
- Listed in CISA KEV (2026-08-18) β this is being exploited in the wild.
- Check the advisory for fixed releases β remediation detail is in the vendor link below.
- CVEs: CVE-2025-62593.
What it is
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
For leadership π§
Executive summary. Risk is Critical (CVSS 9.4) across any Ray-Project kit you run. Follow the remediation in the vendor advisory within Immediate β CISA KEV entries carry a federal remediation deadline.
Why it matters:
- Exposure depends on deployment topology and which access paths reach the affected component.
- Treat internet-facing and management-plane instances as higher risk than internal-only ones.
- Keep monitoring for abnormal authentication and configuration events until upgrades complete.
Now / Next / Later:
- Now: confirm whether you run the affected versions, and check exposure of any that are internet-facing.
- Next: apply the remediation the advisory specifies, through an approved change window.
- Later: add a control check so builds cannot drift back onto a vulnerable train.