Listen to this Post
CVE-2025-62593 is a critical remote code execution vulnerability affecting Ray, a distributed AI/ML compute framework, in versions prior to 2.52.0. The vulnerability stems from an insufficient defense mechanism implemented by Ray to protect against browser-based attacks on local Ray nodes.
Ray’s dashboard and job API endpoints (such as `/api/jobs` and /api/job_agent/jobs/) have historically lacked authentication. To prevent browser-originated requests from reaching these sensitive endpoints, Ray implemented a middleware check that inspects the `User-Agent` header. Specifically, the `is_browser_request()` function checks whether the `User-Agent` header starts with the string “Mozilla”. If so, the request is rejected with a `405 Method Not Allowed` response.
This defense relies on the assumption that browsers cannot modify the `User-Agent` header. However, the `fetch` specification allows the `User-Agent` header to be set to arbitrary values in both Firefox and Safari. Ironically, Chrome is not vulnerable because of a bug that prevents `User-Agent` manipulation, making it non-compliant with the specification.
An attacker can combine this `User-Agent` header manipulation with a DNS rebinding attack. In a DNS rebinding attack, a malicious website first resolves to the attacker’s IP, then after the victim visits the site, the DNS response changes to resolve to `127.0.0.1` (localhost). This allows the malicious website’s JavaScript to make `fetch` requests to `127.0.0.1:8265` (the Ray dashboard port) with a spoofed `User-Agent` that does not start with “Mozilla”. Since the request bypasses the `User-Agent` check, it reaches the unauthenticated Ray API endpoints, allowing the attacker’s JavaScript to submit jobs and execute arbitrary code on the victim’s machine. The attack is triggered when a developer running Ray inadvertently visits a malicious website or is served a malicious advertisement (malvertising).
DailyCVE Form:
Platform: Ray AI compute engine
Version: < 2.52.0
Vulnerability: RCE via DNS rebinding
Severity: CRITICAL (CVSS 9.4)
Date: 2025-11-26
Prediction: Patch expected 2025-11-26 (2.52.0)
What Undercode Say:
Check Ray version pip show ray | grep Version Upgrade to patched version pip install --upgrade ray==2.52.0 Verify upgrade python -c "import ray; print(ray.<strong>version</strong>)" Stop Ray services if not in use ray stop Check running Ray dashboard port netstat -tulpn | grep 8265 Block external access to dashboard port (temporary mitigation) iptables -A INPUT -p tcp --dport 8265 -s 127.0.0.1 -j ACCEPT iptables -A INPUT -p tcp --dport 8265 -j DROP
Exploit: (Educational Purposes!)
- Attacker sets up a DNS rebinding server (e.g., NCCGroup/Singularity)
- Victim (running Ray locally) visits the attacker’s malicious website
- Malicious site executes DNS rebinding to resolve to 127.0.0.1
- JavaScript sends `fetch` request to `http://127.0.0.1:8265/api/jobs` with a custom `User-Agent` not starting with “Mozilla”
- Ray’s `User-Agent` check is bypassed; the unauthenticated API accepts the request
- Attacker submits a job with arbitrary code to execute on the victim’s machine
Protection:
– Upgrade Ray to version 2.52.0 or later immediately
– Use Google Chrome for development browsing (not vulnerable)
– Stop Ray Dashboard when not in use (ray stop)
– Configure firewall to restrict access to port 8265 to localhost only
– Enable token-based authentication by setting `RAY_AUTH_MODE=token`
Impact:
- Attackers can execute arbitrary code on the developer’s machine
- Complete compromise of confidentiality, integrity, and availability (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- Affects all Ray users running versions prior to 2.52.0 who use Firefox or Safari
- No authentication required; only user interaction (visiting a malicious site) is needed
- Potential for malvertising campaigns targeting Ray developers
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: www.cve.org
Extra Source Hub:
Undercode

