CVE-2025-62593 is a critical code-injection vulnerability in Ray versions earlier than 2.52.0. Ray Dashboard attempted to block browser-originated requests to sensitive job-management functionality by treating User-Agent values beginning with "Mozilla" as browser traffic. This is not an effective security boundary because Firefox and Safari permit modification of the User-Agent header in the relevant Fetch API scenario. An attacker can combine this bypass with DNS rebinding to cause a victim browser to communicate with a locally running or network-reachable Ray Dashboard and submit a malicious workload. Ray executes the submitted workload with the privileges of the Ray process, resulting in remote code execution. The issue is also associated with CWE-352 due to its browser-mediated request-forgery characteristics.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-62593 affecting Ray. It contains three files: a .gitignore, a README describing the vulnerability and usage, and the main exploit script ray_rce_poc.py. The code is stdlib-only and intended to directly exercise Ray Dashboard HTTP API endpoints rather than relying on the browser-based DNS rebinding scenario mentioned in the README. The exploit workflow is straightforward and operational: it accepts either a single target URL or a file of targets, builds a malicious Ray job entrypoint, submits that job to POST /api/jobs/, polls GET /api/jobs/ until the submitted job reaches a terminal state, and then fetches GET /api/jobs/<submission_id>/logs to recover command output. The payload is attacker-controlled via --command and is wrapped inside a Python one-liner that executes the shell command on the Ray head node, redirects stdout/stderr to a randomized file under /tmp, and prints the captured contents back into the Ray logs. The script includes basic vulnerability triage logic: HTTP 401/403/404 responses are treated as not vulnerable or inaccessible, while HTTP 200 with a returned submission_id is treated as successful job submission. It is not merely a detector because it actively executes arbitrary commands and confirms RCE by retrieving output. It supports batch scanning from a targets file and can write a JSON summary of results. Overall, the repository’s purpose is to provide a practical unauthenticated remote code execution PoC against exposed Ray Dashboard instances on port 8265.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
90 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote-code-execution vulnerability affecting Ray, for which the content describes a Nuclei HTTP detection template targeting an exposed Ray dashboard service on port 8265.
An unauthenticated remote code execution vulnerability affecting the Ray API. The content describes a Nuclei detection template targeting Ray job API endpoints, including POST /api/jobs/ and GET /api/jobs/{{jobid}}/logs.
A browser-guard bypass vulnerability in the Ray Dashboard that can lead to remote code execution (RCE). The content references Ray versions 2.51.1 and 2.52.0 in the context of a Nuclei template, but does not establish affected or fixed version boundaries.
A high-severity vulnerability affecting Anyscale Ray, identified as CVE-2025-62593. The provided CVSS vectors indicate network reachability, low attack complexity, no required privileges, user interaction, and high impacts to confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.