Cybersecurity
CISA orders federal agencies to patch a critical flaw in the Ray AI framework
The code-injection vulnerability, actively exploited via a browser-based attack, carries a 9.4 CVSS score and a three-day federal remediation deadline.
Original cover art, generated for this story. THE VISSION does not republish third-party press imagery.
The short version
- CISA added CVE-2025-62593, a critical code-injection flaw in the open-source Ray distributed computing framework, to its Known Exploited Vulnerabilities catalog on August 17.
- The flaw, rated 9.4 on the CVSS scale, allows remote code execution via a DNS-rebinding attack through browsers including Firefox and Safari, exploiting unauthenticated Ray API endpoints.
- Federal civilian agencies have until August 20 to patch under Binding Operational Directive 26-04; the fix ships in Ray version 2.52.0.
- Ray is used to scale AI and machine learning workloads and has more than 43,500 stars on GitHub.
The code-injection vulnerability, actively exploited via a browser-based attack, carries a 9.4 CVSS score and a three-day federal remediation deadline.