CISA Adds Actively Exploited Ray Flaw CVE-2025-62593 to KEV
This digest was compiled by AI from multiple sources — links to the originals are below.

CISA on Monday added CVE-2025-62593, a critical Ray framework vulnerability, to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaw has a CVSS score of 9.4 and enables remote code execution via DNS rebinding in Firefox and Safari. Ray maintainers fixed the issue in Python package version 2.52.0.
Key Facts
- CVE-2025-62593 has a CVSS score of 9.4 and can be triggered through a DNS rebinding attack against Firefox or Safari browsers.
- Ray maintainers fixed the flaw in Python package version 2.52.0.
- BitSight reported in March 2026 that RondoDox botnet operators added the exploit two days before its public disclosure on Nov 26, 2025.
- Oligo said ShadowRay 2.0 targeted unpatched Ray instances with NVIDIA GPUs to build a self-replicating cryptocurrency mining botnet.
- The Ray GitHub repository had more than 43,500 stars and 7,900 forks as of the article date.
The Ray Flaw
CVE-2025-62593 carries a CVSS score of 9.4 and enables remote code execution through browser-based DNS rebinding attacks. Ray maintainers traced the flaw to the absence of authentication on critical endpoints such as /api/jobs and /api/job_agent/jobs/. Attackers can modify the User-Agent header so that a developer who visits a malicious website or sees a malicious advertisement triggers execution of arbitrary shell code. The attack can also use the browser as a confused deputy to reach network-adjacent Ray instances inside private corporate networks. The Ray GitHub repository had more than 43,500 stars and 7,900 forks as of the article date.
Fix and Exploitation
Ray maintainers fixed the vulnerability in Python package version 2.52.0. Ray credited Oligo security researcher Avi Lumelsky with discovering the fetch bypass and Jonathan Leitschuh with developing the DNS rebinding attack. CISA has not disclosed details of how the vulnerability is being exploited in the wild. BitSight reported in March 2026 that RondoDox DDoS botnet operators incorporated the exploit two days before its public disclosure on Nov 26, 2025. According to Oligo, ShadowRay 2.0 targeted unpatched Ray instances with NVIDIA GPUs to build a self-replicating cryptocurrency mining botnet.
5 sources
CISA Adds Actively Exploited Ray Flaw CVE-2025-62593 to KEV



