DEV Community

Achin Bansal
Achin Bansal

Posted on Originally published at gridthegrey.com

CVE-2025-62593: Ray AI Framework RCE via DNS Rebinding

Forensic Summary

CISA has added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, flagging a critical flaw in the Ray distributed AI/ML computing framework that enables remote code execution through DNS rebinding attacks via Firefox and Safari. The vulnerability stems from Ray's longstanding absence of authentication on critical API endpoints, allowing attackers to execute arbitrary shell code on developer machines or pivot into private corporate networks. Active exploitation has been observed by the RondoDox DDoS botnet and a self-replicating GPU cryptomining campaign dubbed ShadowRay 2.0.


Read the full technical deep-dive on Grid the Grey: https://gridthegrey.com/posts/cve-2025-62593-ray-ai-framework-rce-via-dns-rebinding/

Top comments (0)