Vulnerability threat dossier

CVE-2025-62593

anyscaleray

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

VTP deterministic threat58.0of 100 · CVSS excluded

VTP analyst assessment

Ray browser-mediated code execution

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this Ray vulnerability as exploited. In Ray versions before 2.52.0, insufficient browser-request defenses can allow code execution through Firefox or Safari.

Why it matters

  • A developer using Ray could be induced to access a malicious browser-delivered attack, leading to code execution in the Ray environment.

Evidence

3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

Public Nuclei tooling does not prove successful exploitation against a given deployment.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

If you use Ray before 2.52.0, upgrade to 2.52.0 or later.

AI baseline history (8)
  1. BASELINE ASSESSED
    Ray browser-mediated code executiongpt-5.6-terra · low
  2. BASELINE ASSESSED
    Ray browser-based code execution is known exploitedgpt-5.6-terra · low
  3. BASELINE ASSESSED
    CISA KEV lists exploited Ray browser-based code injection flawgpt-5.6-terra · low
  4. BASELINE ASSESSED
    Browser-assisted code injection against Ray development deploymentsgpt-5.6-sol · high
  5. BASELINE ASSESSED
    Ray code injection vulnerabilitygpt-5.6-sol · high
  6. BASELINE ASSESSED
    Ray code-injection vulnerability in CISA KEVgpt-5.6-sol · high
  7. BASELINE ASSESSED
    Ray code-injection vulnerability listed in CISA KEVgpt-5.6-sol · high
  8. BASELINE ASSESSED
    KEV-listed vulnerability with technical details pendinggpt-5.6-sol · high

Previous AI priority: HIGH → current: HIGH. Inspect the evidence preserved for each run before treating this as a threat transition.

Technical severityCRITICALCVSS 9.4 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.6299th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.62; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EPSS MATERIAL INCREASEEPSS changed materially from 0.27 to 0.62
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
KEV UPDATEDCISA KEV record updated
03

Claim provenance

Evidence and source independence

3publications detected
3underlying evidence chains

0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:NUCLEI:391230a54ea1c842d14a1b66e45945ecdddc2177ACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:f9a87680b8e409a842fa8b44babd07d99fe6d20e521183068db724e669477331ACTIVE
Evidence
Source claimEXPLOITATION REPORTEDPUBLICATION REPORTS EXPLOITATION
60%claim confidence
UNKNOWNreport:9c09e46dbe8a3e0996e73e42d6f59dbb22d9bfbf52647b01ac073f3e051a3c70ACTIVE
Evidence
04

Event history

Threat timeline

  1. 17:4525 Sept
    EPSS MATERIAL INCREASE

    EPSS changed materially from 0.27 to 0.62

    Predictive context changed; this is not exploitation evidence.

  2. 07:2824 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  3. 15:1121 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.

  4. 06:3418 Aug
    EXPLOITATION REPORTED

    Exploitation Reported

    The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

  5. 00:0018 Aug
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

  6. 17:3417 Aug
    KEV UPDATED

    CISA KEV record updated

    Official KEV fields changed: due_date.

05

Original publications

Source record

Exploit tooling coverage changed for 3 CVEs

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 3 CVEs in this pinned revision. 3 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2025-34033CVE-2025-62593CVE-2026-56681
Separate evidence group
Original

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek .

CVE-2025-62593
Separate evidence group
Original

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

CVE-2025-62593
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score58.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction12.49 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration2 / 10
CVSS technical severityExcluded
CVSS
9.4 · CRITICAL
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-352, CWE-94
CPE records
1
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.