🚨SEVERITY: CRITICAL — CVSS 9.4Security Advisory

TL;DR 📌

  • Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
  • Highest CVSS: 9.4 (Critical).
  • Listed in CISA KEV (2026-08-18) — this is being exploited in the wild.
  • Check the advisory for fixed releases — remediation detail is in the vendor link below.
  • CVEs: CVE-2025-62593.

What it is

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.