CVE-2025-62593Critical▾ Hadal⚠ Exploited in the wildPoC availableRay is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…
▾ Hadal zone — Critical and actively exploited (CISA KEV / 0day)
impact 52.3 · likelihood 3.4 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Aug 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
Federal remediation due Aug 20, 2026
0.4%
0.4% → 17%
critical → none
none → critical
critical → none
none → critical
critical → none
none → critical
critical → none
none → critical
critical → none
none → critical
critical → none
none → critical
2 GitHub repos (last check)
Added to the CISA catalog on Aug 17, 2026. Federal remediation due Aug 20, 2026. View catalog ↗
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
ray < 2.52.0Patched in:
ray 2.52.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6019Critical· 9.8Ray OS Command Injection vulnerability
CVE-2023-48022Critical· 9.8Ray has arbitrary code execution via jobs submission API
CVE-2023-6020Critical· 9.3Ray Missing Authorization vulnerability
CVE-2023-6021Critical· 9.3Ray Path Traversal vulnerability
CVE-2025-34351CriticalRay's New Token Authentication is Disabled By Default
CVE-2025-1979Medium· 6.4ray vulnerable to Insertion of Sensitive Information into Log File