Ray Remote Code Execution (unauthenticated)

Author: danangrismanto255-specCreated Aug 22, 2026Updated Sep 8, 2026
Labelstemplate-requests

Is there an existing template for this?

  • I have searched the existing templates.

Template requests

  • CVE-2025-62593

Anything else?

PoC: https://github.com/Boreas37/CVE-2025-62593-PoC

Proof-of-concept for CVE-2025-62593, an unauthenticated Remote Code Execution vulnerability in the Ray distributed AI compute engine, abused via browser-based DNS-rebinding attacks. It was added to the CISA Known Exploited Vulnerabilities (KEV) catalog and is actively exploited.

(CVSS 9.4, KEV): Unauthenticated server-side RCE on exposed Ray Dashboards, reachable via DNS rebinding in Firefox/Safari.

Source: projectdiscovery/nuclei-templates