Improper authentication in Ray - CVE-2025-62593

 

Improper authentication in Ray - CVE-2025-62593

Published: December 11, 2025 / Updated: August 17, 2026


Vulnerability identifier: #VU119863
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62593
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to improper authentication implemented on "/api/jobs" and "/api/job_agent/jobs/" endpoints. A remote attacker can trick the victim into visiting a malicious website and force the victim's browser into sending a crafted payload to the affected endpoints available at the developer's machine, resulting in remote code execution. 


Affected software

Ray
Red Hat OpenShift AI (RHOAI)
AI Inference Server

How to mitigate CVE-2025-62593

Install updates from vendor's website.

Ray - update to 2.52.0
Red Hat OpenShift AI (RHOAI) - update to 2.25.1
AI Inference Server - update to 3.2.5

External References

Related Security Bulletins