Ray RCE Vulnerability: A Near Miss
CISA has identified that some bold attackers are exploiting a significant weakness in Ray, the open-source tool for scaling Python and machine-learning applications. Known as CVE-2025-62593 and rated 9.4 on the CVSS v4 scale, this flaw was initially discovered in November 2025. It allows attackers to execute remote code (RCE) on Ray systems that are outdated using Firefox or Safari.
The Deceptive Workaround
This Ray software, which stands alongside major players like Amazon, Apple, and OpenAI, attempts to thwart browser requests by verifying if the User-Agent header begins with “Mozilla.” However, the sneaky features of Firefox and Safari enable scripts utilizing the Fetch API to manipulate that header. Therefore, if a developer is tinkering with Ray and accidentally visits a shady site or clicks on a malicious ad, they could encounter significant trouble.
An Insight into the Attack
“This flaw targets developers engaged in development/testing with Ray,” the experts behind Ray indicated. “If they fall victim to a phishing attack or a questionable advertisement, bingo! They find arbitrary shell code executing on their machine.”
The Network Deception
But there’s additional concern! This can also compromise nearby Ray instances by using the browser as an unwitting intermediary to attack Ray instances within a private corporate network. The release of Ray 2.52.0 addresses this vulnerability, so make sure to update!
The CISA Urgency
CISA has given federal agencies in the US just three days to resolve this issue, a departure from the standard two weeks. There’s no clarity on the urgency, but they possess the authority to enforce a short three-day remediation period when circumstances become critical.
Ray’s Origins and Influence
Ray is an open-source framework that assists developers in scaling Python and machine-learning tasks with greater ease. It is currently supported by the Linux Foundation’s PyTorch Foundation, having originated at UC Berkeley and transitioned to a commercial entity through Anyscale in 2019.
Ray’s Remarkable Expansion
As of October 2025, Ray has achieved over 237 million downloads, averaging 7 million weekly! NextSprints estimates that Ray boasts a million active monthly users and is utilized by 60% of Fortune 500 companies. That’s some serious impact!
Security Weakness
The advisory points out that Ray has been somewhat negligent regarding authentication on critical endpoints, paving the way for this issue. Ray’s security strategy involved operating clusters within a trusted, isolated network, leaving authentication and access control to the broader network. The introduction of Ray 2.52.0 brings optional token-based authentication for enhanced security, though it remains disabled by default. They continue to emphasize the importance of maintaining clusters within a secured network as opposed to relying solely on authentication.
Conclusion: Who Needs Rest Anyway?
Therefore, if you haven’t updated Ray yet, take action now, unless you are eager for a significant security nightmare. A three-day fix? Hope you didn’t have any major plans for the weekend, right?