[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-62593":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-18T10:37:34.217Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":85,"aliases":95,"duplicate_of":9,"upstream":98,"downstream":99,"duplicates":100,"related":101,"reserved_at":9,"published_at":104,"modified_at":105,"state":106,"summary":107,"references_raw":117,"kevs":183,"epss":193,"epss_history":195,"metrics":452,"affected":467},"CVE-2025-62593","Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string \"Mozilla\" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.",null,[11,62],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-94","Improper Control of Generation of Code ('Code Injection')","The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.","weakness","Draft","Base","Medium",[20,24,58],{"id":21,"name":22,"techniques":23},"CAPEC-242","Code Injection",[],{"id":25,"name":26,"techniques":27},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[28,39,46],{"id":29,"name":30,"tactics":31,"countermeasures":38},"T1027.006","HTML Smuggling",[32,35],{"id":33,"name":34},"TA0030","Defense Evasion",{"id":36,"name":37},"TA0005","Stealth",[],{"id":40,"name":41,"tactics":42,"countermeasures":45},"T1027.009","Embedded Payloads",[43,44],{"id":33,"name":34},{"id":36,"name":37},[],{"id":47,"name":48,"tactics":49,"countermeasures":52},"T1564.009","Resource Forking",[50,51],{"id":33,"name":34},{"id":36,"name":37},[53],{"id":54,"name":55,"tactic":56},"D3-FFV","File Format Verification",{"name":57},"Isolate",{"id":59,"name":60,"techniques":61},"CAPEC-77","Manipulating User-Controlled Variables",[],{"_key":63,"id":63,"name":64,"description":65,"type":15,"status":66,"abstraction":67,"likelihood_of_exploit":18,"capec":68},"CWE-352","Cross-Site Request Forgery (CSRF)","The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.","Stable","Compound",[69,73,77,81],{"id":70,"name":71,"techniques":72},"CAPEC-111","JSON Hijacking (aka JavaScript Hijacking)",[],{"id":74,"name":75,"techniques":76},"CAPEC-462","Cross-Domain Search Timing",[],{"id":78,"name":79,"techniques":80},"CAPEC-467","Cross Site Identification",[],{"id":82,"name":83,"techniques":84},"CAPEC-62","Cross Site Request Forgery",[],[86],{"_key":87,"name":88,"source":89,"url":90,"maturity":91,"reliability_score":92,"verified":93,"type":9,"platforms":94,"requires_auth":9,"exploitdb":9,"metasploit":9},"GITHUB_RAY-PROJECT_RAY","Ray","github","https://github.com/ray-project/ray/security/advisories/GHSA-q5fh-2hc8-f6rq","poc",0.3,false,[],[96,97],"GHSA-q279-jhrf-cc6v","PYSEC-2026-520",[],[],[],[102],{"_key":103},"CGA-9GR6-8JWM-Q9C2","2025-11-26T22:28:28.577Z","2026-08-18T03:55:33.677Z","Analyzed",{"cisa_kev":108,"cisa_ransomware":93,"cisa_vendor":109,"epss_severity":110,"epss_score":111,"severity":112,"severity_score":113,"severity_version":114,"severity_source":115,"severity_vector":116,"severity_status":106},true,"Ray-Project","low",0.00369,"critical",9.4,"v4.0","cve.org","CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H",[118,129,134,139,143,147,151,156,160,164,168,172,177],{"url":119,"sources":120,"tags":123},"https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v",[115,121,122],"nvd","osv_pypi",[124,125,126,127,128],"X Refsource CONFIRM","WEB","Exploit","Patch","Vendor Advisory",{"url":130,"sources":131,"tags":132},"https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09",[115,121,122],[133,125,127],"X Refsource MISC",{"url":135,"sources":136,"tags":137},"https://nvd.nist.gov/vuln/detail/CVE-2025-62593",[122],[138],"Advisory",{"url":140,"sources":141,"tags":142},"https://github.com/nccgroup/singularity/pull/68",[122],[125],{"url":144,"sources":145,"tags":146},"https://docs.ray.io/en/releases-2.51.1/ray-security/index.html",[122],[125],{"url":148,"sources":149,"tags":150},"https://en.wikipedia.org/wiki/Malvertising",[122],[125],{"url":152,"sources":153,"tags":154},"https://github.com/ray-project/ray",[122],[155],"PACKAGE",{"url":157,"sources":158,"tags":159},"https://github.com/ray-project/ray/blob/e7889ae542bf0188610bc8b06d274cbf53790cbd/python/ray/dashboard/http_server_head.py#L184-L196",[122],[125],{"url":161,"sources":162,"tags":163},"https://github.com/ray-project/ray/blob/f39a860436dca3ed5b9dfae84bd867ac10c84dc6/python/ray/dashboard/optional_utils.py#L129-L155",[122],[125],{"url":165,"sources":166,"tags":167},"https://pypi.org/project/ray",[122],[155],{"url":169,"sources":170,"tags":171},"https://github.com/advisories/GHSA-q279-jhrf-cc6v",[122],[138],{"url":173,"sources":174,"tags":175},"https://www.bitsight.com/blog/rondodox-botnet-infrastructure-analysis",[115,121],[176],"Third Party Advisory",{"url":178,"sources":179,"tags":180},"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62593",[115,121],[181,182],"Government Resource","US Government Resource",[184],{"source":185,"vendor":109,"product":88,"date_added":186,"vulnerability_name":187,"short_description":188,"required_action":189,"due_date":190,"known_ransomware_campaign_use":191,"notes":192,"exploitation_type":9},"cisa","2026-08-17","Ray-Project Ray Code Injection Vulnerability","Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.","Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","2026-08-20","Unknown","https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v ; https://github.com/ray-project/ray/commit/70e7c72780bdec075dba6cad1afe0832772bfe09 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2025-62593",{"date":186,"score":111,"percentile":194},0.29942,[196,200,203,206,209,212,216,219,222,225,228,231,234,237,240,243,245,248,251,254,257,260,264,267,270,273,275,277,280,282,285,288,292,295,298,301,304,307,310,312,315,317,319,322,325,328,331,334,336,338,340,342,344,347,350,353,356,359,361,364,367,370,373,376,378,381,384,387,390,393,396,399,402,405,408,411,413,416,419,422,425,428,430,433,436,438,441,444,446,449],{"date":197,"score":198,"percentile":199},"2025-11-27",0.00021,0.046,{"date":201,"score":198,"percentile":202},"2025-11-28",0.0459,{"date":204,"score":198,"percentile":205},"2025-11-29",0.04647,{"date":207,"score":198,"percentile":208},"2025-11-30",0.04651,{"date":210,"score":198,"percentile":211},"2025-12-01",0.0475,{"date":213,"score":214,"percentile":215},"2025-12-02",0.00028,0.06933,{"date":217,"score":214,"percentile":218},"2025-12-03",0.06948,{"date":220,"score":214,"percentile":221},"2025-12-04",0.06927,{"date":223,"score":214,"percentile":224},"2025-12-05",0.06971,{"date":226,"score":214,"percentile":227},"2025-12-06",0.06983,{"date":229,"score":214,"percentile":230},"2025-12-07",0.06982,{"date":232,"score":214,"percentile":233},"2025-12-08",0.06991,{"date":235,"score":214,"percentile":236},"2025-12-09",0.07046,{"date":238,"score":214,"percentile":239},"2025-12-10",0.0712,{"date":241,"score":214,"percentile":242},"2025-12-11",0.0714,{"date":244,"score":214,"percentile":242},"2025-12-12",{"date":246,"score":214,"percentile":247},"2025-12-13",0.07152,{"date":249,"score":214,"percentile":250},"2025-12-14",0.07143,{"date":252,"score":214,"percentile":253},"2025-12-15",0.07101,{"date":255,"score":214,"percentile":256},"2025-12-16",0.07136,{"date":258,"score":214,"percentile":259},"2025-12-17",0.07226,{"date":261,"score":262,"percentile":263},"2025-12-18",0.00009,0.00697,{"date":265,"score":262,"percentile":266},"2025-12-19",0.00699,{"date":268,"score":262,"percentile":269},"2025-12-20",0.00698,{"date":271,"score":262,"percentile":272},"2025-12-21",0.00695,{"date":274,"score":262,"percentile":263},"2025-12-22",{"date":276,"score":262,"percentile":263},"2025-12-23",{"date":278,"score":262,"percentile":279},"2025-12-24",0.00701,{"date":281,"score":262,"percentile":279},"2025-12-25",{"date":283,"score":262,"percentile":284},"2025-12-26",0.00706,{"date":286,"score":262,"percentile":287},"2025-12-27",0.00702,{"date":289,"score":290,"percentile":291},"2025-12-28",0.0001,0.00823,{"date":293,"score":290,"percentile":294},"2025-12-29",0.00822,{"date":296,"score":290,"percentile":297},"2025-12-30",0.0082,{"date":299,"score":290,"percentile":300},"2025-12-31",0.00817,{"date":302,"score":290,"percentile":303},"2026-01-01",0.00824,{"date":305,"score":290,"percentile":306},"2026-01-02",0.00831,{"date":308,"score":290,"percentile":309},"2026-01-03",0.00834,{"date":311,"score":290,"percentile":294},"2026-01-04",{"date":313,"score":290,"percentile":314},"2026-01-05",0.00828,{"date":316,"score":290,"percentile":303},"2026-01-06",{"date":318,"score":290,"percentile":291},"2026-01-07",{"date":320,"score":290,"percentile":321},"2026-01-08",0.0083,{"date":323,"score":290,"percentile":324},"2026-01-09",0.00841,{"date":326,"score":290,"percentile":327},"2026-01-10",0.00845,{"date":329,"score":290,"percentile":330},"2026-01-11",0.00843,{"date":332,"score":290,"percentile":333},"2026-01-12",0.0084,{"date":335,"score":290,"percentile":333},"2026-01-13",{"date":337,"score":290,"percentile":324},"2026-01-14",{"date":339,"score":290,"percentile":330},"2026-01-15",{"date":341,"score":290,"percentile":330},"2026-01-16",{"date":343,"score":290,"percentile":330},"2026-01-17",{"date":345,"score":290,"percentile":346},"2026-01-18",0.00847,{"date":348,"score":290,"percentile":349},"2026-01-19",0.00844,{"date":351,"score":290,"percentile":352},"2026-01-20",0.00837,{"date":354,"score":290,"percentile":355},"2026-01-21",0.00833,{"date":357,"score":290,"percentile":358},"2026-01-22",0.00835,{"date":360,"score":290,"percentile":327},"2026-01-23",{"date":362,"score":290,"percentile":363},"2026-01-24",0.00852,{"date":365,"score":290,"percentile":366},"2026-01-25",0.00854,{"date":368,"score":290,"percentile":369},"2026-01-26",0.00856,{"date":371,"score":290,"percentile":372},"2026-01-27",0.00861,{"date":374,"score":290,"percentile":375},"2026-01-28",0.00858,{"date":377,"score":290,"percentile":372},"2026-01-29",{"date":379,"score":290,"percentile":380},"2026-01-30",0.00873,{"date":382,"score":290,"percentile":383},"2026-01-31",0.00879,{"date":385,"score":290,"percentile":386},"2026-02-01",0.00888,{"date":388,"score":290,"percentile":389},"2026-02-02",0.00976,{"date":391,"score":290,"percentile":392},"2026-02-03",0.00981,{"date":394,"score":290,"percentile":395},"2026-02-04",0.00979,{"date":397,"score":290,"percentile":398},"2026-02-05",0.00984,{"date":400,"score":290,"percentile":401},"2026-02-06",0.00999,{"date":403,"score":290,"percentile":404},"2026-02-07",0.01012,{"date":406,"score":290,"percentile":407},"2026-02-08",0.01015,{"date":409,"score":290,"percentile":410},"2026-02-09",0.01014,{"date":412,"score":290,"percentile":407},"2026-02-10",{"date":414,"score":290,"percentile":415},"2026-02-11",0.01047,{"date":417,"score":290,"percentile":418},"2026-02-12",0.01066,{"date":420,"score":290,"percentile":421},"2026-02-13",0.01071,{"date":423,"score":290,"percentile":424},"2026-02-14",0.01076,{"date":426,"score":290,"percentile":427},"2026-02-15",0.01079,{"date":429,"score":290,"percentile":424},"2026-02-16",{"date":431,"score":290,"percentile":432},"2026-02-17",0.01064,{"date":434,"score":290,"percentile":435},"2026-02-18",0.01163,{"date":437,"score":290,"percentile":435},"2026-02-19",{"date":439,"score":290,"percentile":440},"2026-02-20",0.01168,{"date":442,"score":290,"percentile":443},"2026-02-21",0.01165,{"date":445,"score":290,"percentile":443},"2026-02-22",{"date":447,"score":290,"percentile":448},"2026-02-23",0.01131,{"date":450,"score":290,"percentile":451},"2026-02-24",0.01109,[453,456,465],{"source":115,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":454},{"baseScore":113,"baseSeverity":455,"vectorString":116,"impactScore":9,"exploitabilityScore":9},"CRITICAL",{"source":121,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":457,"cvss_v4_0":463},{"baseScore":458,"baseSeverity":459,"vectorString":460,"impactScore":461,"exploitabilityScore":462},8.8,"HIGH","CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",9.8,7.2,{"baseScore":113,"baseSeverity":455,"vectorString":464,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",{"source":122,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":466},{"baseScore":113,"baseSeverity":9,"vectorString":116,"impactScore":9,"exploitabilityScore":9},[468,478,485],{"ecosystem":9,"name":469,"vendor":470,"product":469,"cpe_part":471,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":472},"ray","anyscale","a",[473],{"version":474,"is_range":108,"range_type":475,"version_start":9,"version_start_type":9,"version_end":476,"version_end_type":477,"fixed_in":9},"lt2.52.0","cpe","2.52.0","excluding",{"ecosystem":479,"name":469,"vendor":479,"product":469,"cpe_part":9,"purl_type":480,"purl_namespace":9,"purl_name":469,"source":9,"versions":481},"PyPI","pypi",[482],{"version":483,"is_range":108,"range_type":484,"version_start":9,"version_start_type":9,"version_end":476,"version_end_type":477,"fixed_in":9},"lt2_52_0","ecosystem",{"ecosystem":9,"name":469,"vendor":486,"product":469,"cpe_part":471,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":487},"ray-project",[488],{"version":489,"is_range":108,"range_type":115,"version_start":9,"version_start_type":9,"version_end":476,"version_end_type":477,"fixed_in":9},"\u003C 2.52.0"]