← Blog · · df00tech

CISA KEV Adds Ray-Project Ray Code Injection Flaw (CVE-2025-62593) — Actively Exploited

breaking kev Ray-Project CVE-2025-62593

CISA has added CVE-2025-62593, a code injection vulnerability in Ray-Project Ray, to its Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation in the wild. Per the published advisory, the vulnerability could allow remote code execution, with developers using Ray as a development tool exposed to exploitation through the Firefox and Safari browsers. No CVSS score has been published yet, and details on the exact exploitation chain remain limited at this time.

Why It Matters

Ray is widely used as a distributed computing framework for machine learning and AI workloads, and its inclusion in the KEV catalog means federal agencies (and, by extension, any organization following CISA guidance) face mandated remediation timelines. The browser-based exploitation vector — via Firefox and Safari — suggests this may involve a developer-facing interface or dashboard component of Ray rather than the core cluster runtime, though the advisory does not fully specify the mechanism. Organizations running Ray in development or ML/AI pipeline environments should treat this as a priority, particularly where Ray's web-facing components are reachable from browsers used by developers or data scientists.

What Defenders Should Watch For

  • Inventory all systems running Ray, especially any exposing Ray's dashboard, API, or other web-accessible interfaces to developer workstations or browsers.
  • Review network exposure of Ray instances — restrict access to trusted networks/VPNs and avoid exposing management interfaces to the open internet.
  • Watch for anomalous process spawning or code execution originating from Ray-related processes, particularly following browser-initiated requests to Ray endpoints.
  • Monitor for unexpected outbound connections or new child processes from hosts running Ray development environments.
  • Apply vendor patches or mitigations as soon as they are published, and prioritize remediation given active exploitation status.

This is developing intel — full technical details, an official patch, and exploitation specifics were not available in the source advisory as of publication. Track the official GitHub Security Advisory for updates: GHSA-q279-jhrf-cc6v.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.