Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence90%
Public exploitation · VTP factKEV
Assessment
CISA KEV lists this Ray vulnerability as exploited. In Ray versions before 2.52.0, insufficient browser-request defenses can allow code execution through Firefox or Safari.
Why it matters
A developer using Ray could be induced to access a malicious browser-delivered attack, leading to code execution in the Ray environment.
Evidence
3 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
Public Nuclei tooling does not prove successful exploitation against a given deployment.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Next watchpoint
If you use Ray before 2.52.0, upgrade to 2.52.0 or later.
AI baseline history (8)
BASELINE ASSESSED
Ray browser-mediated code executiongpt-5.6-terra · low
BASELINE ASSESSED
Ray browser-based code execution is known exploitedgpt-5.6-terra · low
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
CISA KEV lists this vulnerability as known to be exploited globally.
02
A proof of concept is reported; functional reliability is not established.
03
EPSS is 0.62; this is predictive context, not exploitation evidence.
04
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
02
Material change ledger
What changed
EPSS MATERIAL INCREASEEPSS changed materially from 0.27 to 0.62
EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
KEV UPDATEDCISA KEV record updated
03
Claim provenance
Evidence and source independence
3publications detected
3underlying evidence chains
0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Predictive context changed; this is not exploitation evidence.
07:2824 Sept
EXPLOIT TEMPLATE AVAILABLE
Public exploit-oriented template available
ProjectDiscovery nuclei-templates published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.
15:1121 Aug
EXPLOITATION REPORTED
Exploitation Reported
SecurityWeek supplied a deterministically extracted signal; review the linked evidence before escalation.
06:3418 Aug
EXPLOITATION REPORTED
Exploitation Reported
The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.
00:0018 Aug
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 3 CVEs in this pinned revision. 3 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek .
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.