CVE-2025-62593

9.5 CISA KEV

Ray-Project · Ray

Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.

Executive summary

A critical code injection vulnerability in Ray-Project Ray is currently being actively exploited in the wild, posing an immediate risk of full system compromise.

Vulnerability

This vulnerability involves improper control of generation of code (CWE-94) and Cross-Site Request Forgery (CWE-352). It allows unauthenticated remote attackers to execute arbitrary code on the affected Ray instance.

Business impact

The vulnerability carries a CVSS score of 9.5, reflecting its critical severity. Successful exploitation permits full remote code execution, which can lead to total system takeover, data exfiltration, and lateral movement within the network. Given its inclusion in the CISA KEV catalog, the urgency for remediation is extreme.

Remediation

Immediate Action: Update the Ray package to version 2.52.0 or later immediately.

Proactive Monitoring: Review application logs for suspicious incoming requests and monitor for unexpected child processes spawned by the Ray service.

Compensating Controls: Implement strict network segmentation to limit exposure of the Ray dashboard and API endpoints to trusted internal networks only.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via GitHub.

Analyst recommendation

Due to the critical nature of this vulnerability and the confirmed active exploitation, organizations must prioritize patching Ray to version 2.52.0. Failure to address this flaw leaves infrastructure exposed to high-impact malicious activity.