CISA Flags Actively Exploited Flaw in Ray-Project AI Framework
The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2025-62593, a code injection vulnerability affecting Ray-Project's Ray platform, to its Known Exploited Vulnerabilities (KEV) Catalog. This listing means CISA has confirmed the flaw is being actively used by attackers, making it a priority for organisations using the affected software to patch or mitigate immediately.
CISA's new Binding Operational Directive (BOD 26-04) requires US federal agencies to prioritise fixing high-risk vulnerabilities like this one on any publicly exposed systems, especially where exploitation could give attackers full control. While this directive is mandatory only for federal agencies, CISA is encouraging all organisations, including small and medium businesses, to adopt the same risk-based approach to vulnerability management.
Ray is a popular open-source framework used for building and scaling AI and machine learning applications. Businesses using Ray in their development or production environments should check whether they are running an affected version and apply any available patches or vendor guidance without delay.