CVE- 2025-62593 is a critical remote code execution vulnerability in Ray, a Python framework, identified by CISA. This flaw allows attackers to exploit developers who run Ray locally through a DNS rebinding attack, particularly affecting users of Firefox and Safari browsers. A public proof-of-concept exploit exists, and the vulnerability has been actively exploited in the wild, leading to its addition to CISA's Known Exploited Vulnerabilities catalog.
Affected versions are those before 2.52.0, which includes a patch. Developers are urged to update to version 2.52.0 immediately and implement security measures like enabling optional authentication to mitigate risks.