/Vulnerability Library

Ray < 2.52.0 - Remote Code Execution

CVE-2025-62593
Early Release

Description

Ray versions prior to 2.52.0 allow unauthenticated remote code execution via the job submission API at /api/jobs/. A weak User-Agent heuristic (rejecting Mozilla-prefixed headers) can be bypassed by non-browser clients, enabling arbitrary command execution when the dashboard is network-reachable.

Severity

Critical

CVSS Score

9.8

Exploit Probability

62%

Affected Product

ray

Published Date

September 8, 2026

Template Author

veraptos vaas alpha

CVE-2025-62593.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2025-62593
CWE ID:
cwe-94

References

https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6vhttps://github.com/projectdiscovery/nuclei-templates/issues/16961https://nvd.nist.gov/vuln/detail/CVE-2025-62593

Remediation Steps

Upgrade Ray to version 2.52.0 or later and enable RAY_AUTH_MODE=token. Restrict dashboard access to trusted networks.