Ray, Remote Code Execution (RCE), CVE-2025-62593 (CRITICAL) -DC-Aug2026-1538

Listen to this Post

CVE-2025-62593 is a critical remote code execution vulnerability affecting Ray, a distributed AI/ML compute framework, in versions prior to 2.52.0. The vulnerability stems from an insufficient defense mechanism implemented by Ray to protect against browser-based attacks on local Ray nodes.
Ray’s dashboard and job API endpoints (such as `/api/jobs` and /api/job_agent/jobs/) have historically lacked authentication. To prevent browser-originated requests from reaching these sensitive endpoints, Ray implemented a middleware check that inspects the `User-Agent` header. Specifically, the `is_browser_request()` function checks whether the `User-Agent` header starts with the string “Mozilla”. If so, the request is rejected with a `405 Method Not Allowed` response.
This defense relies on the assumption that browsers cannot modify the `User-Agent` header. However, the `fetch` specification allows the `User-Agent` header to be set to arbitrary values in both Firefox and Safari. Ironically, Chrome is not vulnerable because of a bug that prevents `User-Agent` manipulation, making it non-compliant with the specification.
An attacker can combine this `User-Agent` header manipulation with a DNS rebinding attack. In a DNS rebinding attack, a malicious website first resolves to the attacker’s IP, then after the victim visits the site, the DNS response changes to resolve to `127.0.0.1` (localhost). This allows the malicious website’s JavaScript to make `fetch` requests to `127.0.0.1:8265` (the Ray dashboard port) with a spoofed `User-Agent` that does not start with “Mozilla”. Since the request bypasses the `User-Agent` check, it reaches the unauthenticated Ray API endpoints, allowing the attacker’s JavaScript to submit jobs and execute arbitrary code on the victim’s machine. The attack is triggered when a developer running Ray inadvertently visits a malicious website or is served a malicious advertisement (malvertising).

DailyCVE Form:

Platform: Ray AI compute engine
Version: < 2.52.0
Vulnerability: RCE via DNS rebinding
Severity: CRITICAL (CVSS 9.4)
Date: 2025-11-26

Prediction: Patch expected 2025-11-26 (2.52.0)

What Undercode Say:

Check Ray version
pip show ray | grep Version
Upgrade to patched version
pip install --upgrade ray==2.52.0
Verify upgrade
python -c "import ray; print(ray.<strong>version</strong>)"
Stop Ray services if not in use
ray stop
Check running Ray dashboard port
netstat -tulpn | grep 8265
Block external access to dashboard port (temporary mitigation)
iptables -A INPUT -p tcp --dport 8265 -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -p tcp --dport 8265 -j DROP

Exploit: (Educational Purposes!)

  1. Attacker sets up a DNS rebinding server (e.g., NCCGroup/Singularity)
  2. Victim (running Ray locally) visits the attacker’s malicious website
  3. Malicious site executes DNS rebinding to resolve to 127.0.0.1
  4. JavaScript sends `fetch` request to `http://127.0.0.1:8265/api/jobs` with a custom `User-Agent` not starting with “Mozilla”
  5. Ray’s `User-Agent` check is bypassed; the unauthenticated API accepts the request
  6. Attacker submits a job with arbitrary code to execute on the victim’s machine

    Protection:

– Upgrade Ray to version 2.52.0 or later immediately
– Use Google Chrome for development browsing (not vulnerable)
– Stop Ray Dashboard when not in use (ray stop)
– Configure firewall to restrict access to port 8265 to localhost only
– Enable token-based authentication by setting `RAY_AUTH_MODE=token`

Impact:

  • Attackers can execute arbitrary code on the developer’s machine
  • Complete compromise of confidentiality, integrity, and availability (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
  • Affects all Ray users running versions prior to 2.52.0 who use Firefox or Safari
  • No authentication required; only user interaction (visiting a malicious site) is needed
  • Potential for malvertising campaigns targeting Ray developers

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: www.cve.org
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top