[KEV] CVE-2025-62593 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2025-62593 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2025-62593 is a code injection vulnerability in Ray-Project Ray that can enable remote code execution when Ray is used as a development tool and exposed through Firefox or Safari.
Technical Detail
The flaw allows code injection through a browser-based attack surface involving Ray. An attacker who successfully exploits the issue may execute arbitrary code in the affected Ray development environment. Publicly available information does not further specify the required user interaction, affected versions, or the precise injection mechanism.
Exploitation Status
Exploit maturity is assessed as Operational, meaning exploitation capability is available for practical use. CISA has confirmed active exploitation in the wild and added this vulnerability to the Known Exploited Vulnerabilities Catalog on August 17, 2026.
Who Is Targeting This
Reported (research-inferred): No public attribution. CISA notes active exploitation of the Ray browser-based remote code execution vulnerability but does not identify a threat group, ransomware operation, or other actor.
What To Do
Apply the Ray-Project-provided security update or vendor-recommended mitigation immediately, prioritizing systems where Ray is used with Firefox or Safari. CISA KEV guidance requires federal civilian executive branch agencies to patch by September 7, 2026, or apply mitigations. Until remediation is complete, restrict Ray use to trusted development environments, limit exposure to untrusted web content, and monitor Ray-related processes for unexpected child processes or code execution activity. No CVE-specific detection indicators have been publicly provided.