CISA Flags Critical Vulnerability in Ray Framework Amid Real-World Attacks
Hamid Siddiqui
News
No image for this briefing
CISA has added a vulnerability in the Ray framework to its Known Exploited Vulnerabilities catalogue, urging federal agencies to patch by August 20. This code-injection flaw, CVE-2025-62593, enables remote code execution. Ray’s widespread use makes this vulnerability particularly dangerous. Anyscale has released a fix in version 2.52.0. The agency warns that prior versions remain at risk. This vulnerability can be exploited via web browsers, increasing the threat level. The urgency for federal compliance is evident, but private-sector operators should also act swiftly.