CVE-2025-62593 – High Severity RCE in Ray AI Compute Engine

Key takeaways

  • CVE-2025-62593 is a remote code execution flaw in Ray (vendor Anyscale) with a High CVSS v3.1 score (8.8) and a Critical CVSS v4.0 score (9.4).
  • The vulnerability is actively exploited via browser‑based attacks (Firefox, Safari) using DNS rebinding and a mutable User-Agent header.
  • CISA KEV added the issue on 2026‑08‑17; federal agencies have a 3‑day remediation deadline.
  • Upgrade to Ray 2.52.0 or later, or apply the vendor’s patch.
  • Monitor for suspicious DNS‑rebinding traffic and unexpected fetch calls from development workstations.

Overview

CVE-2025-62593 affects the open‑source AI compute engine Ray maintained by Anyscale. The flaw allows an unauthenticated attacker to achieve remote code execution on any machine running a vulnerable Ray node. Exploitation leverages a browser’s ability to modify the User-Agent header (per the fetch specification) and a DNS‑rebinding attack, enabling malicious JavaScript served from a remote site to inject code into the Ray process. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed the vulnerability in its Known Exploited Vulnerabilities (KEV) catalog on 2026‑08‑17 and mandated remediation within three days for federal systems.


Technical Details

  • Root cause – Ray validates incoming HTTP requests by checking that the User-Agent header begins with the string “Mozilla”. This check is intended to block non‑browser traffic, but the fetch API permits arbitrary modification of the header, rendering the guard ineffective.

  • Attack flow

    1. An attacker hosts a malicious web page (or malvertising) that runs JavaScript in a victim’s browser.
    2. The script issues a fetch() request to the Ray node’s internal API, overriding the User-Agent header with a custom value.
    3. Using DNS rebinding, the attacker makes the browser resolve the Ray node’s internal address to a domain they control, bypassing same‑origin restrictions.
    4. The Ray node processes the request and executes attacker‑supplied code, leading to full system compromise.
  • CWE mapping – CWE‑94 (Improper Control of Generation of Code) and CWE‑352 (Cross‑Site Request Forgery).

  • Exploit example (simplified):

fetch('http://vulnerable-ray-node.internal/api/v0/execute', {
  method: 'POST',
  headers: { 'User-Agent': 'malicious-agent' },
  body: JSON.stringify({ cmd: 'rm -rf /' })
});

The request bypasses the naïve “Mozilla” check, and the payload is executed on the Ray node.

  • CVSS scores – CVSS v3.1 8.8 (High) (vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and CVSS v4.0 9.4 (Critical) (vector: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H).

Severity & Impact

MetricValue
CVE IDCVE-2025-62593
VendorAnyscale
ProductRay
Fixed in2.52.0
CVSS v3.18.8 (High)
CVSS v4.09.4 (Critical)
CWECWE‑94, CWE‑352
Exploit StatusActive exploitation
CISA KEVCISA KEV

The combination of remote code execution, no authentication required, and the ability to trigger the flaw via a standard web browser makes this vulnerability highly impactful across cloud, on‑premise, and edge deployments that use Ray for distributed ML workloads.


Affected Products

All versions of Ray prior to 2.52.0 are vulnerable. The vulnerability is present in the default HTTP API server used for job scheduling and cluster management. For a complete list of affected versions and distributions, see the detailed product matrix on the VulnSocial CVE page: https://vulnsocial.com/cve/CVE-2025-62593.


Actionable Insights – What to Do Now

  • Patch immediately – Upgrade every Ray node to version 2.52.0 or later. The official commit fixing the issue is https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09.
  • Enforce network segmentation – Isolate Ray control planes from public‑facing networks and from workstations that run browsers.
  • Disable browser‑based development on production nodes. Use headless or CLI tools that do not rely on a browser’s fetch API.
  • Deploy DNS‑rebinding protection – Block wildcard DNS entries and enforce strict same‑origin policies on internal services.
  • Monitor for anomalous traffic – Look for outbound HTTP requests from Ray nodes to external domains, especially those with unusual User-Agent values.
  • Apply CISA KEV guidance – Federal agencies must complete remediation by 2026‑08‑20 per the CISA KEV directive. Follow BOD 26‑04 patch‑priority guidance.

Remediation & Mitigation Steps

  1. Upgrade – Pull the latest Ray release (pip install -U ray==2.52.0 or use your package manager) and restart all services.
  2. Verify – Confirm the version with ray --version and ensure the commit hash matches 70e7c72780bde….
  3. Restrict access – Configure firewall rules to allow only trusted IP ranges to reach the Ray HTTP API.
  4. Disable unnecessary UI – If the Ray dashboard is not required, disable it or bind it to localhost.
  5. Implement WAF rules – Block inbound requests that contain a User-Agent header not starting with “Mozilla” and that target Ray’s internal endpoints.
  6. Audit logs – Review Ray and web server logs for any fetch attempts with custom User-Agent strings or DNS‑rebinding patterns.
  7. Document compliance – Record remediation actions to satisfy CISA’s 3‑day KEV deadline and internal audit requirements.

Bottom Line

CVE-2025-62593 is a high‑severity remote code execution flaw in Ray that is already being exploited. The fastest path to safety is to upgrade to Ray 2.52.0 (or later) and apply the hardening steps above. Organizations, especially federal agencies, must act within the CISA KEV three‑day window to avoid compliance penalties and potential compromise of AI workloads.


References

#CVE #CVE202562593 #High #RCE #Ray #Anyscale #CISAKEV