The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability affecting Ray, an open source distributed computing framework used for artificial intelligence and machine learning workloads, to its Known Exploited Vulnerabilities (KEV) catalog after identifying evidence of active exploitation. The vulnerability, tracked as CVE 2025 62593, has been assigned a CVSS score of 9.4 and could allow attackers to execute arbitrary code remotely through web browsers such as Mozilla Firefox and Apple Safari by using a DNS rebinding attack technique. Ray is a Python native framework designed to help developers scale AI and machine learning applications, and its open source project has gained significant adoption, with more than 43,500 stars and over 7,900 forks on GitHub.
The vulnerability is linked to insufficient authentication protections on critical Ray endpoints, including /api/jobs and /api/job_agent/jobs/, which have historically lacked access controls. According to an advisory shared by Ray maintainers in November 2025, this design decision contributed to a security issue that enables attackers to execute arbitrary code against Ray environments. The flaw specifically affects browser based attack scenarios where the User Agent header can be modified. When combined with a DNS rebinding attack, the vulnerability can be exploited against developers who are running Ray in development or testing environments and accidentally visit a malicious website or encounter a malicious advertisement. In such cases, an attacker could potentially execute arbitrary shell commands on the affected machine without requiring direct access to the Ray instance. The Ray development team also warned that attackers could extend the attack beyond local environments by using a victim browser as a confused deputy, allowing them to target Ray deployments running within private corporate networks.
The vulnerability has been fixed in Ray version 2.52.0 of the Python package. Ray credited Oligo security researcher Avi Lumelsky for discovering the fetch bypass issue and Jonathan Leitschuh for identifying the DNS rebinding attack technique. While CISA confirmed that the vulnerability is being exploited in the wild, the agency has not provided details about the specific attacks or threat actors using the flaw. However, a BitSight report published in March 2026 indicated that operators behind the RondoDox distributed denial of service botnet had already incorporated the vulnerability into their activities before its public disclosure on November 26, 2025. The availability of a proof of concept exploit reportedly allowed attackers to add the vulnerability to their attack capabilities shortly after it became publicly known.
Security researchers have also linked unpatched Ray instances to attacks aimed at compromising AI infrastructure. According to Oligo, vulnerable Ray clusters equipped with NVIDIA GPUs have been targeted in campaigns designed to convert infected systems into self replicating cryptocurrency mining botnets. The campaign, known as ShadowRay 2.0, highlights the increasing interest from attackers in AI focused infrastructure as organizations continue deploying large scale computing environments. The exploitation of Ray vulnerabilities creates additional risks because compromised clusters may contain valuable computing resources and could provide attackers with access to sensitive development environments. Due to the active exploitation of CVE 2025 62593, CISA has recommended that Federal Civilian Executive Branch agencies apply available security fixes and mitigation measures by August 20, 2026. Organizations using Ray are also advised to update affected deployments and review their configurations to reduce exposure to browser based attacks and unauthorized code execution.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





