Vulnerability
Published 2026-08-17
Verified 2026-09-19

Ray AI compute engine code injection (CVE-2025-62593)

Ray is an AI compute engine. CISA added CVE-2025-62593 to KEV on 17 August 2026. The GitHub advisory and NVD describe a code-injection issue in versions before 2.52.0. Patch to 2.52.0. Do not expose developer Ray services to untrusted networks.

Product
Ray (Anyscale)
Versions
Prior to 2.52.0
CVSS
(CVSS 3.1, NVD)
Exploited in Australia?
unknown
Patch to
2.52.0

Primary: Ray advisory · Vendor: NVD · CVE: CVE-2025-62593 · CISA KEV

tech ai