ZeroDayAlert

CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

Ray-Project Ray Added to KEV 2026-08-17 Federal due 2026-08-20 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Ray-Project Ray is a distributed computing framework used by developers to build and run scalable applications. The vulnerability affects developers using Ray as a development tool, with exploitation possible through Firefox and Safari browsers. The record does not specify which versions of Ray are affected or what deployment architectures carry elevated risk.

How to check whether this touches you

  • Inventory whether Ray is installed in your development environments, data science platforms, or production clusters.
  • Determine whether Ray instances are reachable from the internet or from untrusted networks (including developer laptops running Firefox or Safari).
  • Confirm your Ray version against vendor advisories; note that backported security fixes may exist in patch releases not explicitly listed by the vendor.
  • If Ray is used in a shared development platform, check whether code or notebooks from external sources are executed within Ray jobs.

What to do

  1. Consult Ray-Project's official security advisory for the specific patched versions and apply the vendor's recommended mitigations immediately.
  2. If patching cannot be completed by the federal remediation due date of 26 August 2026, isolate affected Ray instances from untrusted networks and disable browser access to Ray dashboards or APIs.
  3. If you operate Ray as a cloud service, review your compliance obligations under CISA BOD 26-04 and apply the risk-based patching guidance applicable to your environment.
  4. Enable logging on all Ray control-plane components and browser-based access points to capture connection attempts and code execution events.
  5. If mitigations are unavailable and risk cannot be reduced to acceptable levels, discontinue use of Ray until a patch is available.

If you find you were exposed

Exploitation of code injection vulnerabilities typically occurs before public disclosure, so search Ray logs and system audit records for the period preceding 17 August 2026 for unexpected code execution, unusual job submissions, or external browser connections. Check browser history and network logs on development machines for requests to Ray services. Retain and analyse logs for at least 90 days before the advisory date, limited only by your log retention policy.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2025-62593 is being exploited. It cannot tell you whether Ray is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →