Vulnerability
Published 2026-08-17
Verified 2026-09-19
Ray AI compute engine code injection (CVE-2025-62593)
Ray is an AI compute engine. CISA added CVE-2025-62593 to KEV on 17 August 2026. The GitHub advisory and NVD describe a code-injection issue in versions before 2.52.0. Patch to 2.52.0. Do not expose developer Ray services to untrusted networks.
- Product
- Ray (Anyscale)
- Versions
- Prior to 2.52.0
- CVSS
- (CVSS 3.1, NVD)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- 2.52.0
Primary: Ray advisory · Vendor: NVD · CVE: CVE-2025-62593 · CISA KEV
