CVE Tools

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The Hacker NewsBy The Hacker News

Reported exploitedRay

Our summary

CISA has added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a critical flaw in Ray. This vulnerability allows attackers to achieve remote code execution through browsers like Firefox and Safari by leveraging DNS rebinding attacks against unauthenticated endpoints. The issue primarily affects developers using Ray for testing or local environments, potentially exposing adjacent internal network instances if victims visit malicious sites. A fix for this high-severity weakness is available in version 2.52.0 of the Python package.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store