CVE-2025-62593 - CVE House
Back to Database
Status published Critical CVE-2025-62593

Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack

Vulnerability Description

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62593

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

ray-project

View all reports →

Affected Software

ray
Vulnerable Versions:
< 2.52.0

Timeline

Official Publish: November 26th, 2025
Last Modified: November 28th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)