EXPOSURES › CVE-2025-62593
CVE-2025-62593
HIGH ⌖ ON CISA KEV · EXPLOITEDRay-Project's Ray framework has a code injection vulnerability allowing remote code execution exploitable via Firefox and Safari.
Developers using Ray as a development tool face exposure to remote code execution through code injection, exploitable via Firefox and Safari. DIB organizations must ensure Ray is patched or avoided to prevent attackers from executing arbitrary code on development systems, which could compromise build pipelines and supply chains. This is not a zero-day as it is listed in CISA's KEV catalog, indicating active exploitation.
Shame score — A code injection vulnerability enabling remote code execution is actively exploited in the wild (KEV), representing a severe, avoidable failure in secure development practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.