CVE-2025-62593 · Moderate · CISA KEV
Ray-Project Ray Code Injection: Remote Code Execution via Firefox/Safari
Threat Engine Auto-Feed · data current as of 2026-08-18
CVE-2025-62593 is a code injection vulnerability in Ray-Project Ray, enabling remote code execution. This vulnerability is actively exploited in the wild, as confirmed by its inclusion in CISA KEV. Developers using Ray as a development tool are particularly at risk.
- CVSS:
- EPSS percentile: 0.29942
- Exploitation pressure: 43/100 (Moderate)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 30th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability involves a code injection, where an attacker can introduce malicious code into an application. If successful, this can lead to the execution of arbitrary commands on the affected system.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations with development teams using Ray-Project Ray
- Technology companies leveraging Ray for development
- Financial services firms with internal development using Ray
Misconfigurations that escalate it
- Use of Firefox or Safari browsers by developers interacting with Ray
- Lack of strict network segmentation for development environments
- Insufficient monitoring of developer workstations for anomalous activity
High-impact scenarios
- Remote code execution on developer workstations, leading to compromise of development environments
- Lateral movement from a compromised developer machine into broader enterprise networks
- Intellectual property theft or supply chain compromise if development tools are exploited
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor for unusual process execution or network connections originating from developer workstations using Ray
- Implement endpoint detection and response (EDR) solutions to flag suspicious activity related to Ray processes
- Audit browser usage (Firefox/Safari) in development environments for unexpected interactions with Ray
Contain
- Isolate developer workstations suspected of compromise from the network
- Restrict network access for development environments to only necessary resources
- Temporarily suspend use of Ray-Project Ray in affected environments until patched
Patch
- Apply the latest security patches and updates for Ray-Project Ray immediately upon availability
- Ensure all developer tools and browsers (Firefox, Safari) are kept up-to-date with the latest security fixes
Frontier verdict — Moderate
This vulnerability is critical due to confirmed in-the-wild exploitation (CISA KEV) and potential for remote code execution on developer systems, warranting immediate attention.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.