The Cybersecurity and Infrastructure Security Agency has added a critical code-injection vulnerability in the Ray AI framework to its Known Exploited Vulnerabilities catalogue, mandating immediate federal patching.
Key Points
- CISA identified CVE-2025-62593, a code-injection flaw allowing remote attackers to execute arbitrary commands on vulnerable Ray deployments.
- Federal agencies must patch their systems or cease operations by August 20, 2025, due to the high risk of active exploitation.
- The vulnerability is accessible via standard web browsers, significantly lowering the barrier for unauthorized access to AI compute clusters.
- Anyscale, the maintainer of the open-source Ray framework, has released a fix in version 2.52.0 to address the security weakness.
- Ray is widely used to distribute machine-learning workloads across CPU and GPU clusters, often housing sensitive proprietary models and training data.