CISA gives federal agencies three days to patch a Ray AI framework flaw under active attack

Started by Sentinel96, Today at 02:50 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: CISA gives federal agencies three days to patch a Ray AI framework flaw under active attack   Views(Read 57 times)
Active members in this topic:
Sentinel96(1)

Sentinel96

The Cybersecurity and Infrastructure Security Agency added a Ray flaw to its Known Exploited Vulnerabilities catalog on August 17 and gave federal civilian agencies until August 20 to fix it, a remediation window of just three days rather than the older standard two week clock. Ray is an open source distributed computing framework that a huge share of AI and machine learning infrastructure quietly runs on, including workloads at Amazon, Apple and OpenAI, so this is not some obscure library nobody has heard of.

The bug itself, CVE-2025-62593, carries a CVSS score of 9.4 and comes down to a very specific and slightly absurd authentication check. Vulnerable versions of Ray try to block browser based attacks by checking whether the HTTP User-Agent header starts with Mozilla, except Firefox and Safari both let a script using the Fetch API rewrite that header freely. Combine that with a DNS rebinding attack and a developer simply visiting a malicious website, or even loading a compromised ad, can hand an attacker remote code execution against their own locally running Ray instance.

That local machine angle is what makes this one nasty in a different way from a typical internet facing server bug. The target is not some hardened production box behind a firewall, it is a developer's laptop or workstation running Ray for testing, which tends to have far less scrutiny and far more interesting data and credentials sitting around on it. The Ray maintainers put out an advisory back in November 2025 blaming a longstanding decision not to implement authentication on critical endpoints like the jobs API, and this latest exploitation confirms that decision is still costing people.

CISA's shortened three day window comes from a newer risk based directive, BOD 26-04, which replaced the flat fourteen day clock with something that scales the deadline to how dangerous and how automatable a given flaw actually is. Ray checks both boxes since it grants total control post exploitation and researchers say it is being actively targeted by at least one opportunistic botnet campaign as well as more targeted intrusion attempts under the ShadowRay banner.

The fix is available and it is not complicated, upgrade to Ray 2.52.0 or later. The harder problem, as more than one security team has pointed out, is inventory. A lot of organizations genuinely do not have a clean list of every machine quietly running Ray somewhere in a research cluster or a data scientist's environment, and building that list in three days is a much bigger lift than applying the patch once you have found every instance.


Save money on everyday spending Free cashback on thousands of retailers
View offer