Skip to content
COOEY

EXPOSURES › CVE-2025-62593

CVE-2025-62593

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-08-17 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-62593 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Ray-Project's Ray framework has a code injection vulnerability allowing remote code execution exploitable via Firefox and Safari.

Developers using Ray as a development tool face exposure to remote code execution through code injection, exploitable via Firefox and Safari. DIB organizations must ensure Ray is patched or avoided to prevent attackers from executing arbitrary code on development systems, which could compromise build pipelines and supply chains. This is not a zero-day as it is listed in CISA's KEV catalog, indicating active exploitation.

Shame score — A code injection vulnerability enabling remote code execution is actively exploited in the wild (KEV), representing a severe, avoidable failure in secure development practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.