Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string “Mozilla” as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.
Ray's dashboard exposes unauthenticated HTTP endpoints, specifically `/api/jobs` and `/api/job_agent/jobs/`, that accept job submission requests and execute the submitted code. The only browser-based access control in place before version 2.52.0 was a check that the `User-Agent` header begins with the string "Mozilla". This guard assumes browsers cannot override that header, but the fetch specification permits it, and both Firefox and Safari honor that specification. An attacker who can cause a victim to visit a malicious page can therefore craft requests that bypass the check entirely.
The attack combines DNS rebinding with a modified `User-Agent` header. A developer running Ray locally visits a malicious website or is served a malicious advertisement while using Firefox or Safari. The attacker's page performs a DNS rebinding attack to make the victim's browser treat the attacker's domain as resolving to the local Ray dashboard, then uses the fetch API with a non-Mozilla `User-Agent` to POST a crafted job payload to `/api/jobs` or `/api/job_agent/jobs/`. Because no authentication exists on those endpoints and the User-Agent guard is bypassed, Ray executes the submitted job, giving the attacker code execution with the privileges of the Ray process. Chrome is not affected due to a browser-side bug that prevents User-Agent modification via fetch.
This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
If Ray-Project Ray runs inside your authorization boundary, yes. CVE-2025-62593 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 20, 2026. For a FedRAMP-authorized service, an unpatched KEV within your boundary is a finding. You must either remediate it or formally document a mitigation before your assessor and sponsoring agency raise it during review.
Knox does not patch Ray-Project Ray on your behalf. Under the FedRAMP shared-responsibility model, remediating CVE-2025-62593 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The patch is yours to apply; maintaining a defensible compliance posture while you apply it is not something you manage alone.
Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2025-62593 class exposures, on an ongoing basis. That means gaps surface during continuous monitoring rather than only when an assessor flags them at scheduled review time, giving you more lead time to act before a finding becomes a formal record.
Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.
Missing the August 20, 2026 deadline turns CVE-2025-62593 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Remediating on time keeps your authorization record clean and the agency relationship intact.
Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.









_Horizontal_RGB.png)









