CISA added CVE-2025-62593, a code-injection vulnerability in the open-source Ray AI framework, to its Known Exploited Vulnerabilities catalogue on 17 August, giving federal agencies until 20 August to patch or stop running it. The flaw allows unauthenticated remote code execution and is unusually reachable through an ordinary web browser rather than requiring direct network access. Anyscale, which maintains Ray, fixed the issue in version 2.52.0; deployments on earlier versions remain exposed. Ray clusters have been targeted before, notably in the ShadowRay campaign tied to a separate older flaw that compromised over 230,000 exposed servers for cryptomining and data theft. CISA currently lists ransomware use as unknown, but recommends locating any Ray deployment, checking external reachability, restricting access, and upgrading immediately.

4m read timeFrom thenextweb.com
Post cover image

Questions this post answers

What is CVE-2025-62593 in the Ray AI framework and is it being actively exploited?

CVE-2025-62593 is a code-injection vulnerability in the Ray AI framework that allows unauthenticated remote code execution. CISA added it to its Known Exploited Vulnerabilities catalogue on 17 August, confirming active exploitation, and gave federal agencies until 20 August to patch or stop running the software. It is unusually reachable through an ordinary web browser rather than requiring direct network access. Track actively exploited CVEs like this one in AI infrastructure by following security coverage on daily.dev.

Which version of Ray fixes CVE-2025-62593?

Anyscale fixed the code-injection vulnerability CVE-2025-62593 in Ray version 2.52.0. Any deployment running an earlier release remains exposed to remote code execution and should be upgraded immediately, especially since the flaw can be triggered through a regular web browser such as Firefox or Safari without direct network access to the Ray service. Developers patching AI pipeline dependencies can keep up with fixes like this via daily.dev.

Has Ray been targeted by attackers before this CVE?

Yes, researchers at Oligo Security documented a campaign called ShadowRay tied to a separate, older Ray vulnerability, in which more than 230,000 internet-exposed servers were scanned and compromised for cryptocurrency mining, credential theft, and theft of source code and models. That earlier flaw is distinct from CVE-2025-62593 but illustrates what exposed Ray infrastructure attracts. Anyone securing ML compute clusters can follow recurring Ray attack patterns like ShadowRay on daily.dev.

33 Impressions