Ray < 2.52.0 - Remote Code Execution
CVE-2025-62593
Early Release
Description
Ray versions prior to 2.52.0 allow unauthenticated remote code execution via the job submission API at /api/jobs/. A weak User-Agent heuristic (rejecting Mozilla-prefixed headers) can be bypassed by non-browser clients, enabling arbitrary command execution when the dashboard is network-reachable.
Severity
Critical
CVSS Score
9.8
Exploit Probability
62%
Affected Product
ray
Published Date
September 8, 2026
Template Author
veraptos vaas alpha
CVE-2025-62593.yaml
9.8Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-62593
CWE ID:
cwe-94
Remediation Steps
Upgrade Ray to version 2.52.0 or later and enable RAY_AUTH_MODE=token. Restrict dashboard access to trusted networks.