Ray-Project Ray Code Injection Vulnerability

🚨SEVERITY: HIGH — CVSS 8.8Security Advisory

TL;DR 📌

  • Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string “Mozilla”…
  • Highest CVSS: 8.8 (High).
  • Listed in CISA KEV (2026-08-17) — this is being exploited in the wild.
  • Fixed in 2.52.0 — upgrade to this release or later.
  • CVEs: CVE-2025-62593.

What it is

CVE-2025-62593 is a code injection flaw in Ray, the AI compute engine, affecting versions prior to 2.52.0. The vulnerability sits in Ray’s protection against browser-based attacks on its local developer interfaces.

Ray’s existing defence checks that the User-Agent header starts with “Mozilla” before accepting requests, on the assumption that this restricts access to genuine browsers behaving normally. This is not a reliable control: the fetch specification permits scripts to set an arbitrary User-Agent header, so a malicious page can simply supply one that satisfies the check.

The realistic attack path requires a developer running Ray to visit a malicious website, or load a malicious advertisement, in Firefox or Safari. The attacking page combines the spoofed User-Agent with a DNS rebinding attack, which lets script on that page resolve a domain to the victim’s local address after the browser has already granted it same-origin permissions. This lets the attacker’s script reach Ray’s local endpoint from inside the browser as if it were a same-origin request, bypassing the User-Agent check and resulting in remote code execution on the developer’s machine. No prior authentication to Ray is needed; the trigger is the developer’s browser visiting attacker-controlled content, not direct network access to Ray itself.

The CVSS vector confirms this shape: network attack vector, low complexity, no privileges required, but user interaction is required, with full impact to confidentiality, integrity and availability. The vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 17 August 2026, so it is known to be exploited.

What to do

  • Upgrade Ray to version 2.52.0 or later, where this issue is patched.
  • Treat any host running Ray as a development tool as exposed to this issue until patched, since exploitation runs through the developer’s browser rather than direct network access to Ray.
  • Given the KEV listing, prioritise this patch above its CVSS score would otherwise suggest and confirm remediation across all developer workstations and CI/build environments running Ray, not just production nodes.
  • Where Ray is used with Firefox or Safari for local development, be aware these are the browsers named as exploitable; patching Ray itself is the fix rather than relying on browser-side mitigations.
  • Consult the advisory for further detail on the DNS rebinding mechanism if you need to assess exposure in environments where Ray cannot be upgraded immediately.

For leadership 🧭

Executive summary. Any machine running Ray as a development tool is at risk of full remote code execution if the developer simply browses to a malicious site or ad in Firefox or Safari; this is already listed as a known exploited vulnerability. Given that status, patching to Ray 2.52.0 should be treated as urgent, not routine.

Why it matters:

  • Ray’s protection against browser-based attacks relies solely on checking that the User-Agent header starts with ‘Mozilla’, a value any script can set via the fetch API
  • A DNS rebinding attack lets an attacker’s page satisfy same-origin checks and then reach Ray’s local endpoint as if it were legitimate, with no authentication or direct network access needed
  • The attack triggers through normal developer browsing behaviour - visiting a compromised site or malvertising in Firefox or Safari - not through exposed infrastructure
  • This is listed in CISA’s Known Exploited Vulnerabilities catalogue, meaning exploitation is confirmed, and the CVSS impact covers full confidentiality, integrity and availability loss on the developer’s machine

Now / Next / Later:

  • Now: Identify every workstation, laptop and CI/build environment running Ray as a development tool, particularly those where developers use Firefox or Safari.
  • Next: Upgrade Ray to version 2.52.0 or later across all identified hosts, treating this as a priority patch given its KEV listing rather than scheduling it by CVSS score alone.
  • Later: Establish a process for tracking and patching AI/ML developer tooling like Ray with the same urgency as production software, since these local interfaces can be reached through browser-based attacks rather than only through direct network exposure.

Source