CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Reported exploitedRayOur summary
CISA has added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a critical flaw in Ray. This vulnerability allows attackers to achieve remote code execution through browsers like Firefox and Safari by leveraging DNS rebinding attacks against unauthenticated endpoints. The issue primarily affects developers using Ray for testing or local environments, potentially exposing adjacent internal network instances if victims visit malicious sites. A fix for this high-severity weakness is available in version 2.52.0 of the Python package.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.