2026-08-18HIGHexploitedA developer's own browser is the attack path into a local Ray cluster, CISA catalogued the flaw as exploited on 17 August
Ray dashboard code injection, unauthenticated job-submission endpoints guarded only by a User-Agent string check, bypassable from Firefox and Safari via fetch() combined with DNS rebinding, reaching code execution on the host running Ray. Fixed in Ray 2.52.0; CISA KEV-listed 2026-08-17.
cve · CVE-2025-62593
Coverage
1
first 2026-08-18 → last 2026-08-18
Latest activity
2026-08-18
A developer's own browser is the attack path into a local Ray cluster, CISA catalogued the flaw as exploited…
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, technology · regions: europe
Sources cited
2
2 hosts
Action items (1)
Do-now tasks recorded on the entries about CVE-2025-62593, newest first. Check the date before acting on an older one.
- Inventory Ray installations on developer, research and data-engineering endpoints (including local2026-08-18CVE-2025-62593
ray startclusters that were never considered internet-facing) upgrade them to 2.52.0 or later, and explicitly enable the authentication feature that release adds, because it ships disabled.
Defender insights
What each entry about CVE-2025-62593 tells a defender to do, newest first.
Triage · detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (3 across 3 tactics)
3 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessDrive-by Compromise
- ExecutionCommand and Scripting Interpreter: Python
- Lateral MovementExploitation of Remote Services
Initial Access TA0001
T1189Drive-by Compromise×1
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a browser exist (i.e., Drive-by Target), including:
Evidence: 2026-08-18/cve-2025-62593-ray-dashboard-dns-rebinding-browser-rce-kev · ATT&CK page ↗
Execution TA0002
T1059.006Command and Scripting Interpreter: Python×1
Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform many functions. Python can be executed interactively from the command-line (via the <code>python.exe</code> interpreter) or via scripts (.py) that can be written and distributed to different systems. Python code can also be compiled into binary executables.
Evidence: 2026-08-18/cve-2025-62593-ray-dashboard-dns-rebinding-browser-rce-kev · ATT&CK page ↗
Lateral Movement TA0008
T1210Exploitation of Remote Services×1
Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. A common goal for post-compromise exploitation of remote services is for lateral movement to enable access to a remote system.
Evidence: 2026-08-18/cve-2025-62593-ray-dashboard-dns-rebinding-browser-rce-kev · ATT&CK page ↗
Entries about Ray dashboard code injection, unauthenticated job-submission endpoints guarded only by a User-Agent string check, bypassable from Firefox and Safari via fetch() combined with DNS rebinding, reaching code execution on the host running Ray. Fixed in Ray 2.52.0; CISA KEV-listed 2026-08-17. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Ray×1
Where this entity is cited
Source distribution
- cisa.gov1 (50%)
- github.com1 (50%)