Ray Remote Code Execution (unauthenticated)
Author: danangrismanto255-specCreated Aug 22, 2026Updated Sep 8, 2026
Labelstemplate-requests
Is there an existing template for this?
- I have searched the existing templates.
Template requests
- CVE-2025-62593
Anything else?
PoC: https://github.com/Boreas37/CVE-2025-62593-PoC
Proof-of-concept for CVE-2025-62593, an unauthenticated Remote Code Execution vulnerability in the Ray distributed AI compute engine, abused via browser-based DNS-rebinding attacks. It was added to the CISA Known Exploited Vulnerabilities (KEV) catalog and is actively exploited.
(CVSS 9.4, KEV): Unauthenticated server-side RCE on exposed Ray Dashboards, reachable via DNS rebinding in Firefox/Safari.
Source: projectdiscovery/nuclei-templates