THREAT OPS › CVEs › CVE-2025-62593
CVE-2025-62593 — Ray-Project Ray Code Injection Vulnerability
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
Vulnerability details
- Affected productsRay
- KEV remediation due2026-08-20
Related reporting
- August 2026 CVE Landscaperecordedfuture
- CISA Adds One Known Exploited Vulnerability to Catalogcisa_advisories
- [NVD] CVE-2025-62593 — Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the cnvd
- [CISA KEV] CVE-2025-62593 — Ray-Project Ray: Ray-Project Ray Code Injection Vulnerabilitycisa_kev