Full research report

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

Original reporting โ†—
โ˜… Threat intelligence assessment high confidence

Executive assessment

CVE-2025-62593 affects Ray instances where user browsers (notably Firefox and Safari) interact with Ray dashboards, mainly in development or test settings. Attackers can craft malicious web content that, via DNS rebinding, bypasses weak User-Agent-based checks, leading to remote code execution. The vulnerability was exploited both before and after its public disclosure, including by DDoS botnet and crypto-miner campaigns. Defensive guidance is clear: patch to 2.52.0 or above, enable token auth, and restrict browser access to Ray interfaces. While high-profile exploitation is confirmed, the full extent of ShadowRay 2.0 and RondoDox campaign activity remains incompletely mapped.

What happened

A critical remote code execution vulnerability (CVE-2025-62593) in Ray permitted browser-based RCE via DNS rebinding, with CISA confirming active exploitation as of mid-August 2026. Both historical and current campaigns have leveraged this flaw, especially targeting developers using Ray for AI/ML workloads.

Affected scope

Ray prior to 2.52.0, especially developer and test deployments exposed to browser use of Firefox or Safari. Network-adjacent Ray clusters are further at risk through browser-based pivot attacks.

Technical assessment

The flaw stems from insufficient authentication and trust in browser headers, allowing User-Agent modification and subsequent DNS rebinding, enabling attacker-controlled code execution via a developer's browser session.

Recommended defensive actions

  1. Immediately patch Ray to version 2.52.0 or later.
  2. Enable token authentication for all Ray deployments.
  3. Restrict browser access to Ray interfaces, especially in development environments.
  4. Audit for any unauthorised or unexpected jobs created on Ray clusters since November 2025.

Uncertainties and evidence gaps

  • CISA and sources have not provided detail on the precise in-the-wild exploitation technique.
  • The prevalence and scale of vulnerable Ray instances, especially in corporate environments, remains unclear.
  • The full set of indicators for ShadowRay 2.0 and RondoDox overlap is incompletely documented.

Vulnerability flow

Defender-oriented path reconstructed only from sourced report findings. Unknown stages are omitted.

AccessBrowser-based access via Firefox or Safari to a Ray deployment interface, often during development or testing.
ComponentRay dashboard / API endpoints (notably /api/jobs & /api/job_agent/jobs/).
MechanismInsufficient authentication/authorisation checks and reliance on User-Agent for defence, allowing DNS rebinding.
ImpactRemote code execution as the user running the browser.
DetectionUnexpected job creation or shell execution from browsers or unfamiliar sources.
MitigationUpgrade to Ray >=2.52.0 and enable token authentication.
Exploitation status

CISA confirms active exploitation in the wild.

Investigation began with reports of active exploitation flagged by CISA for a critical Ray vulnerability. Official vulnerability, vendor, and advisory sources were examined to confirm product scope, exploitation mechanism, and patch status. Campaign and OSINT links were sought, with evidence confirming usage in criminal botnet campaigns but limited operational detail from CISA. Dual confirmation from vendor and government was achieved, supporting a high-confidence assessment.

  1. Is CVE-2025-62593 actively exploited and what is its root cause?
    Reviewed The Hacker News article and followed its source claims.
    thehackernews.com โ†—

    CISA and multiple sources report active exploitation; DNS rebinding in Firefox/Safari exploits Ray without auth.

    why Established credible exploitation claims, scope, and rough mechanism.

  2. What details does the NVD advisory provide?
    Fetched official CVE summary.
    nvd.nist.gov โ†—

    Critical RCE prior to v2.52.0, mechanism matches press and vendor advisories.

    why Confirms timeline, affected versions, and severity.

  3. Is a vendor patch or workaround available?
    Checked GitHub release and advisory pages.
    github.com โ†—

    Patched in 2.52.0; token auth introduced.

    why Confirms fixed version and additional mitigation.

  4. Is there an official vulnerability or exploit advisory from the project?
    Reviewed GitHub security advisory for details and timeline.

    Public PoC was released following coordinated disclosure; details reinforce DNS rebinding vector.

    why Primary technical resource; substantiates exploitation pathway and credits researchers.

  5. Has CISA confirmed the KEV status?
    Searched CISA KEV catalog for the CVE.

    Listed with patch/mitigation advisory; due date for US Federal action.

    why Completes government confirmation and priorities for patching.

ActorsRondoDox DDoS botnet operatorsShadowRay 2.0 campaign actors
MalwareRondoDoxShadowRay 2.0
TargetsDevelopers running Ray in dev/test environmentsNetwork-adjacent Ray clusters
Related CVEs CVE-2025-62593

Research coverage

All 68 registered source leaves were evaluated for this run: 61 completed, 0 were unavailable, 0 failed and 7 were disabled. For this story, 5 registered sources supplied useful evidence (3 primary, 1 corroborating, 1 contextual and 0 PoC/exploit references). 56 completed sources contained no matched information for this story.

Primary evidence Independent corroboration Operational context PoC reference Checked โ€” no match Unavailable Failed Disabled
Complete source-by-source audit 68 sources
SourceRun resultValueWhy it was useful โ€” or not
CISA KEVkev ok1670 records Primary evidence1 matched items Confirmed that a related CVE is listed in CISA's Known Exploited Vulnerabilities catalogue.
NVDcve ok900 records Primary evidence1 matched items Supplied a vendor or government advisory opened and verified during focused research.
The Hacker Newsnews ok9 records Primary evidence1 matched items Published the source report used to frame and date the event.
CISA Alertsnews ok empty0 records Corroborating1 matched items A page from this source was opened and verified during focused research.
FIRST EPSSepss ok7785 records Context1 matched items Added exploitation-probability context; EPSS does not itself prove exploitation.
AlienVault OTXdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
BleepingComputernews ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
CIRCL CVEcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco PSIRTvendor_advisory ok5324 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Cisco Talosnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
deepdarkCTI CVE most exploiteddeepdarkcti ok94 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Discorddeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI exploitsdeepdarkcti ok24 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI forumsdeepdarkcti ok264 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware as a servicedeepdarkcti ok7 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI malware samplesdeepdarkcti ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI marketsdeepdarkcti ok127 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI phishingdeepdarkcti ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI ransomware gangsdeepdarkcti ok685 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI RATsdeepdarkcti ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram infostealerdeepdarkcti ok130 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Telegram threat actorsdeepdarkcti ok1009 records Checked โ€” no match The source completed, but none of its retained records matched this story.
deepdarkCTI Twitter threat actorsdeepdarkcti ok39 records Checked โ€” no match The source completed, but none of its retained records matched this story.
DNSDumpster domain IOC enrichmentresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Exploit-DBexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Fortinet PSIRTvendor_advisory disabled Disabled Disabled in the source registry; no check was attempted.
GitHub topic: cveresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: exploitresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: penetration-testingresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: pocresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GitHub topic: vulnerabilityresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
GreyNoiseexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
KrebsOnSecuritynews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
LinkedIn RSS proxy feeds (disabled)research disabled Disabled Disabled in the source registry; no check was attempted.
MalwareBazaardark_web ok2 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cveresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #cybersecurityresearch ok16 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #exploitresearch ok15 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #infosecresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #malwareresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #ransomwareresearch ok19 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #threatintelresearch ok15 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Mastodon #vulnerabilityresearch ok20 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Metasploit module metadataexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Microsoft MSRCvendor_advisory ok1590 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Microsoft Securitynews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP Galaxyresearch ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
MISP threat actor galaxyactor ok0 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Palo Alto Networks PSIRTvendor_advisory ok25 records Checked โ€” no match The source completed, but none of its retained records matched this story.
ProjectDiscovery nuclei templatesexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Rapid7news ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Reddit r/AskNetsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/cybersecurity (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/malware (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/netsec (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
Reddit r/ReverseEngineering (pending API approval)research disabled Disabled Disabled in the source registry; no check was attempted.
SANS ISCnews ok1 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Shadowserver public aggregate honeypot observationsexploit_reference ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Shodanresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Sigma Rulesresearch ok3 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Sophos IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
ThreatFoxthreat_intelligence ok100 records Checked โ€” no match The source completed, but none of its retained records matched this story.
UK NCSCnews ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
Unit42 IOCsresearch ok empty0 records Checked โ€” no match The source completed but returned no records in the collection scope.
URLhausdark_web ok10 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VirusTotal Community IOC enrichmentresearch ok4 records Checked โ€” no match The source completed, but none of its retained records matched this story.
VulnCheck KEVkev ok500 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Vulnerability Lookupcve ok30 records Checked โ€” no match The source completed, but none of its retained records matched this story.
Additional verified pages 5 opened outside the registered collection
Vulnerability & exploitation2
CVE-2025-62593 CISA KEV Ray-Project Ray ยท added 2026-08-17 CISA catalog โ†—
CVE-2025-62593 EPSS 1.0% 60th percentile exploitation probability
Technical references2
github.com/ray-project/ray โ†—

Repository captured from the source article as technical context; not validated as PoC or exploit code.

github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v โ†—

Repository captured from the source article as technical context; not validated as PoC or exploit code.

Vendor & gov advisories2
NVD - CVE-2025-62593 nvd.nist.gov โ†—

Official vulnerability listing summarising impact and patch.

Release Ray-2.52.0 ยท ray-project/ray github.com โ†—

Release notes identifying fixed version and token authentication introduction.

Analysis & research1
The Hacker News: CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE thehackernews.com โ†—

News article summarising vendor and community reporting; reference for timeline and actor links.